I can only speak for myself - I consider it more safe to trust different parties for encryption and storage of data. Keepass don't know how to get to my dropbox, dropbox doesn't know how to unlock my keepass file.
Can't speak for OP, but I maintain my standalone 1password app and have resisted upgrading to the subscription version because I already have enough subscriptions in my life and this is not a problem that needs a dedicated service. With the standalone version I am in control of when and how my passwords are synced over the net. The sub service adds little value for me and introduces costs and complications I am not really interested in.
Well, guess because he trusts Dropbox but not 1Password or LastPass. Makes sense as they stand out "passwords are here".
It's flexible and there are many storage options so just don't use Dropbox, if you don't trust it as well. Install Syncthing[1]. Or just use any SFTP-capable SSH server you have and can trust to hold the encrypted data. Or enable password-protected[2] WebDAV under some path on any of your nginx or Apache servers. Or set up Nextcloud.
___
[1] If you use KeepassXC, it would be a little noisy about the lock files. I heard the plan is to just remove those (and always merge on save) as they don't serve their purpose any well. Same as with Dropbox, though.
[2] It could be also certificate-protected, but software support may vary.
For me: Dropbox treats my data as dead text, mostly. The password people want to track what accounts I have, add favicons, all sorts of parsing and storage with expectations—and so opportunity for error.
> The password people want to track what accounts I have, add favicons, all sorts of parsing and storage with expectations—and so opportunity for error.
1) They can't read your data.
2) They can see your favicons, but users like this feature. In Bitwarden, you can disable it.
3) Furthermore, Bitwarden is completely open source and you can decide on which cloud or server you want to host. Although using a good password is much more important.
Because in principle the files on Dropbox could just be dumped on the open internet -- Dropbox never sees anything unencrcypted. There is a lot more trust in a single tool.
EDIT: No, I'm wrong. I was thinking in terms of login credentials (which neither are able to see); but LastPass does look at the URLs associated with your credentials so they can pull favicons
A random DropBox isn’t a tempting target to break into, but a security flaw with 1Password might open up the data of tens (hundreds?) of thousands of accounts.