With news about recent hacks, I’m looking forward to having ways and means on Tezos to protect my Ledger-derived tz1 pre-existing baker management address by way of multisig.
Or implement what MvX did in approval. No need to overcomplicate, right?
Multisig feels beefier though. Solution ties in with PQ migration.
for seed generation I wouldn’t trust anything javascript based. for historical reasons getting good entropy was very hard there so many hacky solutions were developed. I would hope all of these have been purged, but who knows. Metamask probably does things reasonably and you could import that.
trust a better hardware vendor to be using the TRNG correctly, or if you’re paranoid about Dual_EC_DRBG still you do it yourself. sample lots and lots of independent noise: dice rolls, sensor LSB, lava lamps, whatever. hash and xor it all together.
but yes, multisigs and key rotations. stateful accounts should have these.
if you have to ask, i recommend not doing it yourself
take a picture with a point and shoot camera, preferably raw, take it to a clean computer/liveboot, sha256sum image.DNG, BIP39 the result, destroy the memory card, import to whatever hardware. Ledger or Trezor are fine choices.