I appreciate the thoughtful response!
The pros of a self made 2/3 multivendor multisig (not using a 3rd party custodian) that matter, imo, are:
1) One malicious firmware update can't rug you
2) Bad entropy for seed generation
3) Supply chain attack for the HWW you use in singlesig
4) Some geographical distribution that could thwart/delay a $5 wrench attack
Now that of course comes with tradeoffs of complexity, possible footguns, higher transaction costs, etc...
While I love the idea of keeping it as simple as possible, the thought that some rogue employee could have manipulated one coldcard before it shipped and that could drain one's life savings with absolutely no recourse is quite a scary thought.
The addition of passphrase to singlesig does mitigate some of these problems, but only if you are verifying that the device is indeed 'using' the passphrase.