It makes sense to benchmark threshold-signing against multi-sigs, but
having good threshold signing would be nice:

 - Wouldn't have to design multi-sigs into every protocol

 - Bandwidth savings (e.g. transmitting m signatures and n public keys
for certificates)

 - Compute savings (e.g. verifying cert chains or secure boot on
low-end devices)

 - Some schemes have additional properties, e.g. proactive schemes let
you redistribute a set of n shares if there's still a secure
threshold, to recover from compromises

 - The anonymity aspect Tim mentioned - how you handle shares /
proactivization could be used to fingerprint parties in an anonymous


