> this seems to be an area where it's really worth investing money in getting the more reliable solution.
You're stating that "Free as in Beer" == "Less Reliable" and the fact that something costs money implies with 100% accuracy that it is reliable. Neither of these are true. Arguing that I'm bringing up a strawman because I said "Free vs. Millions of Dollars" instead of "Free vs. $50" is beside the point.
And I never even came close to saying that "something costs money implies with 100% accuracy that it is reliable". You are once again making up words to put in my mouth.
The fact is, a lot of people still believe the "open source == more eyeballs" myth, even though that is a myth. Open source does not equate to reliability. And when it comes to software that requires this much trust, a company built around a product is more inherently trustworthy than open source, as the entire company is on the line with their product (and the livelihood of all their employees), whereas with the open source product only the reputation of the author(s) is at stake.
Please note that, once again, I am not saying this is a "100% accurate" indicator of reliability. There are many factors at play. One important factor would be whether the software in question has ever undergone a security audit. Another would be whether there's proper documentation on the encryption (i.e. 1Password's file format is completely documented, both so third party software can use it if need be, and so the security of the file format can be vetted). A third would be the involvement of anyone who is already previously known to be an expert in the field. Etc.
Edit: Come on guys, please stop drive-by downvoting. If you disagree, comment!
Edit: And hates being told they hate it. How meta. If you disagree, please leave a comment. Drive-by downvoting does not help anyone.
On the other hand, AgileBits (makers of 1Password) is a company, with actual money on the line (in addition to reputation) serving as an assurance that the product will not only continue to be developed, but will remain secure.
If KeePass screws up, some reputation is lost, people may switch to another product, and the developer(s) can just move on to working on other software if KeePass can't be salvaged. If AgileBits screws up, not only is reputation lost, but so are paying customers, depending on the severity the entire company might go belly-up (e.g. if 1Password is compromised heavily enough that it can't be trusted anymore), a lot of people are suddenly out of a job, etc. Basically, there's a lot more at stake for AgileBits, which makes it much easier to trust that not only are they going to do their job right, but they're also going to have processes in place to ensure a build never gets released externally that doesn't pass QA, etc.
And don't forget that as a paying customer of AgileBits, I can get support from them for any problem I might be having. Open source projects don't typically employ support personnel, and generally rely on the community to try and provide whatever support they can.
---
Ultimately, this comes down to the fact that this is a specialized class of software, where one breach can mean irreparable damage as the attacker now has access to your passwords for everything. For that kind of software, I really want the backing of a company, with a significant amount to lose, rather than just some unknown collection of open source developers.
Which is to say, for nearly any other class of software, I'm much more inclined to judge it based on its merits, and open source has a lot of advantages. But this isn't any other class of software.
I might be a strange case, but I just have this feeling "real" companies spend their $$$ on meetings in Bahamas and Ferraris, while FOSS/OSS would be more open to security audits/etc.
A company with money on the line can (also) easily be shut down or aquired. I imagine a FOSS/OSS team would be demanding more guarantees for the future of the project, while "in it for the money" companies would take the check and not give a damn if it was shut down the same day.
"Real" companies often seem to push releases/features (prematurely?) to attract new customers. That the new features pass review/QA doesn't necessarily mean they are implemented right (goto fail?). In addition FOSS/OSS have public bug trackers, I'd rather know there are x number of bugs labeled "security" in my os, than not beeing told at all.
Support can (should?) be where open source make money, there are lots of FOSS/OSS projects out there offering paid support/installations/sass.
And the unknown collection of open source developers _may_ be a much better collection of security specialists/coders than in the "real" company. As most of FOSS/OSS is done voluntarily you don't have to pay huge paychecks for top of the line expertise.
Bottom line, I trust Debian (& co) and Mozilla. I don't trust Microsoft, Apple and Google.
This is 100% biased as to what I think. I understand that this is a two sided issue, and fully understand people who think like you sketched out. I'm just not one of those people :P