Can you elaborate on this? What do you mean by 'protected' and 'high entropy key'? It makes it sound like they aren't key stretching, which seems unlikely. Can you provide a source here?
> Worse, they use dynamically-downloaded JavaScript to handle your password, which means even if you use a high-entropy passphrase Mozilla can at any time send you malicious JavaScript and snarf your passphrase.
I'm unsure why you think Mozilla would do this, or why you would be using Firefox at all if you expect them to push malware to your system.
> This means that any government Mozilla must obey can do the same thing.
I'm not sure this is true, mostly because it lacks any sort of precedent.