@Dylan you don't have to trust one vendor at all. dice rolls matter because that entropy is yours and gets mixed with the device rng, so a bad rng on its own can't hand you a predictable seed. a passphrase covers the layer above that, since a device that never sees it can't spend by itself. if you want out of single vendor trust entirely, multisig across two different manufacturers is the real answer, and then the question stops being who do we trust and becomes how many independent things have to fail at once.