Agree this is a strong design but it is 100x more complex and unlikely to be implemented by most people.
I'd also be curious which security vulnerabilities would be of concern to you relative to the design Bitkey is proposing and the setup you describe?
It seems like you have a lot of work ahead, helping people understand the advantages of multisig.
I dont know how to evaluate their proposal.