There's a tension here between "user freedom" and a service wanting to make sure that credentials that it trusts to grant access to stuff aren't just being yolo'd around into textfiles on people's dropboxes.
People forget that one of the purposes of authentication is to protect both the end user and the service operator.