We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word.
Granted, if I had to chose today, I would instantly pick 1Password based on what I can find on google, and LP has far, far more leaks than 1P.
But let's not kid ourselves that 1P is somehow more trustworthy without audits. And I'll eat crow if 1P has proof that they are routinely audited by 3rd parties.
EDIT: removed snark.
EDIT#2: If Signal can publish open source, why cant 1Password? If security is done right, the source code should be visible to everyone without jeopardy, or at least that's what I've been led to believe.
EDIT#3: Thanks for the link y'all, here it is at top level: https://1passwordstatic.com/files/security/1password-white-p... ... mmmm crow
EDIT#4: We trust browsers too much. 1P stores the secret key on every device so that you only have to enter your passphrase. I'd really like that code to be public because that's a great way to lose control of everyone's secret key. Extensions worry me because they are a critical component in any password manager's usability-vs-security. But perhaps that is a digression or worth an Ask HN.