Fair enough. I like the SS photo method. 256 isn't a lot, get it wherever you're comfortable getting it. But if we're trusting implementations of elliptic curve multiplication to produce unique pubkeys seems ok to trust many available RNGs, if we go by number of different autists who obsess over these things.

Replies (2)

That's a separate issue. One is not alternative to the other. Everything flows from the seed. It is the root. If you get poisoned there everything down stream is compromised. Yes, other things need to be secured along the way too, but so what. The entropy of the seed is the basis of the security of everything else
The point is the *reasonable expectation of trust. You trust elliptic curve multiplication only goes one way and cant be unwound. It is a *similar application of trust to use a RNG. Is it necessary? No, use dice if you wanna. But if HWRNG is compromised then the entire security layer of the internet is broken and we have much bigger problems.