> For example, after you have generated your own seed words you trust the firmware to generate your xpub, which could just be someone's else's xpub.
Good point! As you say, multi-vendor solves this. It’s unlikely that multiple independent vendors will be vulnerable at the same time by the same attacker. If multiple independent vendors give you the same XPUB, you’re probably good.
I would argue that rolling your own seeds on a single device is still better than trusting the device to generate the seed because the device may have latent bad randomness. But entering the same seed into multiple devices from different vendors is better still.
In a nutshell, we’re trying to guard against:
1. Bad randomness
2. Known seeds
3. Lying devices
4. Leaked seeds
Rolling your own seeds guards against 1 & 2, but to guard against 3 you need multivendor. To mitigate 4 you need multivendor multisig.