As for Trezor case the private key does not leave the device. I would imagine that the integration would be like most cases where the data gets sent to the hardware wallet to be sent. Signed in the wallet and it spits out the payload to be broadcasted.
As such by using hardware wallets, you shouldn't be exposing private keys outside of ththe device at all.
One of the parent comments said signing happens client side. Another comment said private key never leaves the device.
Which is it? Are both possible?
I really think the option to paste in the private key should be removed. It's dangerous to ask for that when there are so many Android apps that by default get access to paste buffer and can grab that key easily. If I were writing malware that would be my number one focus.
If you have a hardware wallet. You will pass the intent message (sending money, swap, etc) to Trezor. Trezor holds your private key. Signs the message with your private key. Hands the payload back to the client to be broadcasted to the network. This way your private key stays in the hardware wallet, and protected from a compromised computer.
If you use metamask instead. The private key here resides in the browser or your computer rather. I am unsure exactly where the signing happens but it will have to happen within the domain of your computer (at metamask or js) because that is where the key is. Gets back payload to be broadcasted.
Copy pasting private key (totally not recommended) is for cases where say you dont have a metamask or a hardware wallet. The signing is done probably using the js library included by the widget to obtain payload for broadcast.
Nothing should be passed on to a server. Only the signed message needs broadcasting into the ethereum network for the transaction to be included into a block.
How do you get that into the Trezor? Using USB OTG? I only see two buttons there.
The hardware buttons act like the ultimate OK/Cancel button. You can review the transaction address, id, etc on the hardware screen to confirm that you are not getting phished and such. (vs. on the software)
That said, its not recommended to paste your private key anywhere.
Yes
>No network connection is made at all until tx is signed?
There is network connection made to get the rate and broadcast transaction. You can check all the source code here btw https://developer.kyber.network/docs/WidgetGeneratorGuide/