@Jeffrey Goldberg Pardon my ignorance, but wouldn’t it be at least prudent to encrypt using the…
Scott Yates
23

If someone is able to watch traffic on your local interface, they’re already running in a escalated privledge position (sudo or the like)

If they have this, there is nothing to stop them doing a wide variety of bad bad things. They could in theory install their own malicious browser extension that could watch for forms being submitted, and log usernames and passwords — in this situation, it doesn’t matter what 1password does, because it would take place after decryption.