I would love to see if you can prove this. Please see their latest audit:
https://blog.mozilla.org/security/2017/07/18/web-service-aud...
https://medium.com/mozilla-tech/how-firefox-sync-keeps-your-...
When you enter your Firefox Account password, we first strengthen it by applying some cryptographic hashing, and then derive two separate keys: an authentication key, and an encryption key. The authentication key is transmitted to the server to prove that you own the account. A bug in TLS might cause this key to be leaked, and someone who intercepts this key could use it to authenticate to your account. But they cannot use it to access your sync data, because: The encryption key is used to encrypt your sync data before it leaves your machine. Since this key is never transmitted to the server, it cannot be leaked by a bug in TLS like the one that affected Cloudflare.