On the other hand, AgileBits (makers of 1Password) is a company, with actual money on the line (in addition to reputation) serving as an assurance that the product will not only continue to be developed, but will remain secure.
If KeePass screws up, some reputation is lost, people may switch to another product, and the developer(s) can just move on to working on other software if KeePass can't be salvaged. If AgileBits screws up, not only is reputation lost, but so are paying customers, depending on the severity the entire company might go belly-up (e.g. if 1Password is compromised heavily enough that it can't be trusted anymore), a lot of people are suddenly out of a job, etc. Basically, there's a lot more at stake for AgileBits, which makes it much easier to trust that not only are they going to do their job right, but they're also going to have processes in place to ensure a build never gets released externally that doesn't pass QA, etc.
And don't forget that as a paying customer of AgileBits, I can get support from them for any problem I might be having. Open source projects don't typically employ support personnel, and generally rely on the community to try and provide whatever support they can.
---
Ultimately, this comes down to the fact that this is a specialized class of software, where one breach can mean irreparable damage as the attacker now has access to your passwords for everything. For that kind of software, I really want the backing of a company, with a significant amount to lose, rather than just some unknown collection of open source developers.
Which is to say, for nearly any other class of software, I'm much more inclined to judge it based on its merits, and open source has a lot of advantages. But this isn't any other class of software.
I might be a strange case, but I just have this feeling "real" companies spend their $$$ on meetings in Bahamas and Ferraris, while FOSS/OSS would be more open to security audits/etc.
A company with money on the line can (also) easily be shut down or aquired. I imagine a FOSS/OSS team would be demanding more guarantees for the future of the project, while "in it for the money" companies would take the check and not give a damn if it was shut down the same day.
"Real" companies often seem to push releases/features (prematurely?) to attract new customers. That the new features pass review/QA doesn't necessarily mean they are implemented right (goto fail?). In addition FOSS/OSS have public bug trackers, I'd rather know there are x number of bugs labeled "security" in my os, than not beeing told at all.
Support can (should?) be where open source make money, there are lots of FOSS/OSS projects out there offering paid support/installations/sass.
And the unknown collection of open source developers _may_ be a much better collection of security specialists/coders than in the "real" company. As most of FOSS/OSS is done voluntarily you don't have to pay huge paychecks for top of the line expertise.
Bottom line, I trust Debian (& co) and Mozilla. I don't trust Microsoft, Apple and Google.
This is 100% biased as to what I think. I understand that this is a two sided issue, and fully understand people who think like you sketched out. I'm just not one of those people :P