Cas' model is terrible if you don't really trust the person issuing the coins.
It's even worse. Even if you don't doubt Cas' integrity, there are other ways in which your private key may be compromised, such as a bug in his RNG or a gag order from NSA to transmit all private keys to them.
I think I actually have these covered.
I was RNG-paranoid from the start, so all my keys were generated via output of purportedly_secure_RNG xor output of SHA256(salt + n), where salt is a long string I mashed on the keyboard and didn't record, and n is an incrementing number.
Order form NSA can't compel me to transmit keys I didn't keep. period... I see keeping the keys as a bigger threat to my safety than any possible good that could ever come from keeping them. so while (consistent with theory) I can't prove I didn't keep the keys, the case that it's in my rational best interest to not have kept them (or to destroy them presuming that I had) only gets bigger as time goes on.
I trust you Mike, mainly on external observations.
a. I have seen your reputation grow for years in this community
b. I have personally met you and thanks for the free coins!
c. While you seemed interested in profit I believe you have no desire to have to flee the country and be pursued for fraud and etc...
d. There have been plenty of opportunities for you to abscond with all the private keys and you have not.