What happens when they lose it? What happens when someone else gets a copy of the private key?
What happens when every app, website, and mobile OS requires a signature for every single post or message, tying all communication to an identity that the government can retaliate against?
I agree and believe revocation is the most important problem.
With services requiring it, you can just not use them: as long as it does not get mandated (unfortunately, a direction we are heading in), hopefully market self-regulates and privacy conserving options win.
Yes, we all know that's not how that movie plays out :)
The private key would be generated and stored on the most secure hardware security modules like how AWS stores many billions of symetric and asymmetric keys.