> The 1Password authors have been pretty open about how distributed their team is, and how no one single government would be able to convince them to do those kinds of things — the other developers would find out and then the game would be over.
Your options are:
A. Go to jail for contempt of court, which is a crime for which you receive no due process or appeals.
B. Give the control over to the government. Yes, your coworkers will find out about it, but you can always get another job.
Are you actually confident that all of the 1Password devs would choose A? Only one of them has to choose B.
I admire Ladar Levison for shutting down Lavabit rather than running a compromised business, because his bravery is the exception, not the rule. There are far more companies out there who have simply handed over the keys to the government when placed under minor duress, and I'm not sure on what basis you're assuming 1Password is going to be one of the exceptions.
> They are also open about the crypto algorithms they use.
Look, I'm sure the 1Password guys are nice, upstanding people, but implementing crypto correctly is hard, really hard. Sure, they are probably telling the truth about what algorithms they use. But did they implement them correctly? Would they tell you if they hadn't, given it would hurt their business?
> As for KeePass or KeePassX, which version do you use? Which of the dozens and dozens of different implementations do you use? Which database format do they support? Do you build the binaries yourself with trusted compilers? Where do you get those trusted compilers and how can you be sure that they haven’t been compromised?
Obviously security is relative, and you can point out ways in which my process is insecure. Indeed, you missed some (my computer could have a virus that keylogs my passwords--my password DB is on two drives which I connect via USB). But literally all of these apply to 1Password as well, so I don't think any of this proves that KeePass is just as insecure as 1Password.
And very notably, these are all security tradeoffs. I get something for every decrease in security I've accepted. The only thing you get for storing your passwords on someone else's computer is that they store them for you and let you access them from multiple devices, which is not something I want or need. I'm not sure you get anything at all in exchange for your password manager being closed-source--that's entirely for 1Password's benefit, not yours.