Earlier quoted context omitted.
Are there any reasonable attacks against AES-GCM-256 where the key is a mix of a randomly generated 128-bit key and a password? If not then I have no concerns about an attacker cracking my 1Password database.
The password is generally the weak point. If you can remember it any modern computer can guess it in a short time. Which is why password generation is so imporant.
That's not true. A long sentence of your choosing is easy to memorise and plenty long enough to not be able to be guessed by a computer (brute force).