As someone who has done this I take issue with characterizing the certificates as stolen. I exploited a security vulnerability in the device's web UI to extract them, from a piece of equipment I paid for. Its my equipment the provider required me to buy it for service, I can do with it as I please.
I would be in agreement with it if we were using all this to steal service, we just don't want to use their unstable and unacceptable equipment.