Mozilla's protocol purports not to reveal passwords to Mozilla itself, but the security of the system rests on Javascript files delivered from … Mozilla. They can, if they wish, target a user and serve him suborned Javascript which send the plaintext password back. Unlike a tampered build of Firefox itself, which might actually be noticed, this could be a one-shot attack.
Worse, not just Mozilla as an organisation can do this: it can be compelled to do so on behalf of any government which has the power to compel it (or those employees capable of targeting someone).
It's a terrible, terrible change.
Do you mean if a site stores cryptographic information in the url? Or is it the act of syncing with your local machine that introduces surfaces of attack on your local system?