Though the use of passphrase is handled outside of the cipher_keyvalue message, it still has a direct effect on nonce derivations. Trezor Password Manager (v0.6.3.6) currently uses no passphrase (useEmptyPassphrase) on device connections. If this is intended to be left to the implementer on how to handle it, it might be worth noting that it is something that should be taken into consideration directly in the SLIP writeup.