This company has shown multiple times in the past that they can and will change their closed source software's behavior to the detriment of user privacy (remember Apple's on-device image scanning?). Why are you or OP surprised when these things continue to happen on the closed source walled garden?
In theory 1Password has the superior product, as they use MFA for accessing your vault, and your account password only allows access to the encrypted vault (unlike Bitwarden where your account password unlocks everything).
But that is all theory, and you don't really know what really goes on behind the scenes, and it could all just be "theater". It probably isn't, but that's where the trust part comes in.
Personally i doubt that Apple has any nefarious intent, and i believe their intention is to make stuff better and more secure, and that they protect/respect privacy. Again, this is a matter of trust, and i trust Apple.
I don't base my assumptions on blind trust, but actually review their documentation on their services, like iCloud Data Security [^1]. They're pretty open about how they encrypt stuff, and also mention stuff like when using standard iCloud encryption, your backup of messages includes a key that can be used to decrypt the messages in the backup.
I enabled Advanced Data Protection as soon as it became available, and stopped worrying about it. For stuff that i want to keep secret at all costs i use GPG or Cryptomator.
As for Keychain i use a mix of Keychain and 1Password. Keychain for everything "simple" that i don't care about, i.e. websites that requires a login. It plays well with Hide my Email, and offers the path of least resistance. My 1Password usage is mostly stuff that doesn't fit easily into Keychain.
Besides, in this case.. it does not help that you'd also have to exchange hardware
If you’re this distrustful of Apple, your logic should say to not use local Keychain at all. You either trust Apple’s hardware backed E2EE or you don’t trust anything from Apple at all, there’s no picking and choosing when it comes to this sort of thing.
I bet privacy researchers at Apple are facepalming reading these threads thinking people can run their own crypto better than they can.
> thinking people can run their own crypto better than they can
Running or developing ?
You can probably run something like Password Store [1] fairly secure, though you still have to trust the operating system not to leak your secrets, and it turns out that today, regardless of your choice, all major operating systems more or less synchronize your data to the cloud.
I know Linux doesn't do it (Ubuntu tried some Amazon partnership once), but Linux is a poor match for many workplaces where Windows or MacOS are kings. Yes, you can run VSCode (or Vim/Emacs or whatever) on Linux, but running Photoshop, Fusion365 or various other business tools is not as "easy" as on Windows/MacOS, and in the end a company only has so many IT support staffers.