But what is the advantage of entering the key into trezor instead of directly into the web interface. Once the whole key is entered the address is sweapt within seconds (I assume) so even if an attacker was infiltrating the PC, no harm could be done.
Well, considering highly specialized malware for stealing sweeping private keys to Trezor; such malware can disconnect Trezor just at time when it detects private key entered to UI. Then there's enough time (few seconds are actually enough) to send such private key to remote server and let it sweep all balance. Not very likely, yet possible.
However me and stick had some brainstorming about sweeping private keys and although it's not very comfortable, we came with a solution which might satisfy paranoid users. It won't be worth a hassle for small amounts, rather for people sweeping their lifetime savings to Trezor.