>someone with my browser information and name could just mitm me recording the timestamps of requests to protonmail's server and request a password reset.
If they can MITM you, why not steal the password directly, or serve malicious js to get your password?