This is the big fallacy I see whenever someone uses open source just because the source code is public. Unless you're able to perform a full audit yourself, is it really any better than a closed offering like 1Password?
In practice, (a) falls apart if the user doesn't have the knowledge, experience, or time necessary to perform an audit, which is quite likely for security software. And I feel like (b) isn't great either, as there are plenty of examples of major flaws in open source projects that went undetected for long periods - heartbleed is just one example.
There are major unrevealed flaws in all software more complicated than “hello, world.”