But you do bring up a good point. Even though you no longer have to worry about the private key ever even having been calculated anywhere by anyone, you do have to trust two entities to properly put the two key pairs on to the item and at least one entity to have properly added the two public keys together.
Please, I insist, can you come up with an example using
small baby numbers?
I am not sure how to do that. The elliptic curve digital signature algorithm requires the use of some pre-defined constants, none of which are baby numbers.