The article was about RSA 512 which has been known to be weak and crackable for a long time [2].
[0]: https://github.com/eu-digital-green-certificates/dgc-partici...
[1]: https://www.gnupg.org/faq/gnupg-faq.html#no_default_of_rsa40...
[2]: https://it.slashdot.org/story/99/08/29/0213230/512-bit-rsa-k...
Seems like a lot of hassle for a vaccine that is safe and will save your life.
https://threatpost.com/eus-green-pass-vaccination-id-private...
Afaik it was a leaked login, not a leak of the keys.
I would expect them to know where and when that Adolf pass was generated
Passes have been sold (through the clear web and the dark web) but many have also been revoked since. As far as I know, the certificates being sold right now are either someone else's certificate (for places that don't check your ID when you walk in) and certificates generated by people working for places that also give out legitimate certificates, such as some pharmacies and hospitals.
There have been fraudulently obtained passes sold on the dark web. There have also been numerous arrests throughout the whole of Europe for this.
The vast majority of the dark-web suppliers are scammers - many of the adverts include a mix of QRs people have posted to social media and a large number of example QR. Including examples that I have generated in the past and used in presentations / on github.