1password goes through far more hoops than any other password manager I've looked at to ensure complete security, even down to encrypting things like website icons, yet for the people so security conscious to care about that, it being closed source is often a big turn off. The hardware security key company Yubico has a similar disconnect, which they explain here https://www.yubico.com/blog/secure-hardware-vs-open-source/
and, frankly even as someone who typically prefers open source, that's a solid argument; specialty hardware is a necessity for security, and it's just not possible to completely open source that.
So, in short, is there a solid reason why 1password isn't open sourced? Am I wrong and it has been open sourced and what I've read online is just flat out wrong? Or, is it just that they haven't bothered?For most products/services (or companies in general) I wouldn't bother asking, but the fact that 1password do go as far as they do to ensure security really doesnt gel in my mind with them staying closed source.
I'm reasonably confident to still use them for the time being, as their software is well integrated, responsive, feature rich, etc. but I know many people straight up will not recommend any closed source password management software at all, letalone use it. That's made even worse by the fact that, 1password is genuinely quite useful and solid as a bit of software, and coming from some other password managers, it's really one of if not the best, so people straight up refusing to recommend it because of something that's relatively easy to fix, just sort of feels wrong.
I've found a few mentions of this, but most of them are from years back, and most of the replies, frankly aren't very comprehensive. They say that, despite being closed source they still strive for absolute security, there have been extensive independent reviews, etc. but I haven't seen anyone have an actual reason for why being closed source is better for 1password than being open source. (and frankly, if the people I've seen talking about it are to be believed, all of those reasons really seem to be getting interpreted as lady doth protest too much by most people asking about the topic) Now, again, I do believe that 1password do take tons of steps to ensure security and whatnot, but to many, that trust isn't enough.
Why choose an open source alternative to 1Password?
What are the best open source alternatives to 1Password?
Are these 1Password alternatives really free?
And if not, what’s a good alternative for iOS?