It doesn't matter. If you have malware lurking in your computer it will just snarf your passwords from the wire and then you're owned all the same. If you use some sort of auth signing system, the request can just be intercepted and modified on the fly.[0] The Trezor is next to useless even for bitcoin for this very reason. Sure they can't steal your money directly, but just replacing the addresses you see and send to accomplishes exactly the same thing. If your platform isn't trusted, no amount if smart crypto or hardware dongles can make it safe.[1]
[0]: The rebuttal for this will be signing every request with details of it with a hardware dongle, but would you want to do this for every action in your email client? If the answer is "no", you're owned. Ultimate security is unusable, and doesn't really solve anything outside of the most astute of professional users. Just writing this post I would need 4 signatures, one to log in, one to post, one to fix a typo, and yet another to add this footnote. Would I be able to handle that? No way, I'm far too lazy for that.
[1]: The issue is that perfect compromise is impossible to detect. I can be reasonably confident on a heavily sandboxed device like an iPhone that there's little in the way of malware that would affect me. The downside being that I have no tools or methods of analysis if I thought it was compromised. There's no such confidence on the computers I use on a daily basis. I've always thought we have confirmation bias with malicious software. We only notice the dumb stuff while the smart goes unnoticed.