Surely, moving to another service provider is fully legit. However, a hijack with a rogue certificate (say from an undiscovered Diginotar) would not be visible to users - thereby exposing their credentials. So people use TOFU (trust on first use) mechanisms like Certificate Patrol:
http://staff.science.uva.nl/~delaat/rp/2012-2013/p56/present...
The future is of course DANE with DNSSEC, where you put information about the certificate and/or the CA in the DNS.