> I'm curious how you reconcile that against things like the benefits of filling from the extension avoiding the system clipboard & key loggers
I'm mostly punting this to macos. I don't give my kids admin rights on the devices I let them use and in general I think you need a11y access to log keys on mac, granting which requires admin.
AFAIK, modern browsers prevent interaction with the clipboard without user interaction, so using the system clipboard for passwords is not a huge deal. As a mitigation, 1password and other password managers clear the clipboard after a timeout.
On my linux machine, I use a bitwarden CLI in a script that either uses xclip to put the password into the clipboard or xdotool to type it directly. To my understanding, the security model in X is quite a bit worse than that in mac, but I prefer this over using a browser extension.
> the inherent phishing protection that comes from 1Password only suggesting credentials on sites where the URL matches your items
I can't wait for a passwordless world to come. For now, my kids only have credentials on sites that are relatively worthless, and I use U2F on all the sites/services I possibly can that have any value.
On the sites that have value but don't support U2F, I either accept the risk or try to find alternatives. Banks and financial services (I live in the US) are a perennial disappointment here.
I do use the bitwarden app on my iphone, and when you actually go through the password filling feature (instead of just switching to the bitwarden app and searching), it does suggest only those passwords that match the URI you're looking at. I haven't closely examined why I'm okay with this integration but not a browser extension on other platforms, but I am.