Currently there is absolutely no procedure to make a cold storage that is 100% safe. Best case scenario, you get pseudo-random keys. If I get some time in the future, I'll write a small library that translates dice rolls in real world into private key and calculates public address from it. Then you'll be able to run it on a CPU that does not have, will not have and never had any network access and THAT will be safe cold storage.