It doesn't mean it should be easy to do, but it's also completely unacceptable to make a requirement like "users are forbidden to access their private keys".
> by anyone at all
What do you mean by anyone at all? By the owner of the private key. Not by anyone.