Also, knowing your password wouldn't be enough to identify it within a breach, assuming that the breached website does the bare minimum to store them safely (as in, uses a salt).
How about reading a thing or two before jumping to conclusions?
The email gets hashed on your device, and the start of that hash is sent off to the server. The server returns a list of all the hashes that might match. The client then checks that list for complete matches.
>Firefox Monitor gets its data breach information from a publicly searchable source, Have I Been Pwned. If you don’t want your email address to show up in this database, visit the opt-out page.
1. Right now Firefox Monitor uses your Firefox account for signups. For somebody like me who already has a Firefox account, I don't see a net difference in risk here.
2. If you don't want to make one, then Monitor is transparent in that they just use https://haveibeenpwned.com under the hood (source: https://support.mozilla.org/en-US/kb/firefox-monitor-faq#w_h...), which doesn't require anything more than submitting your email and passing their Google captcha. It's unfortunate that they're not more forthcoming about this, but the option is there.
I think this is a great functionality and it will really help the average user.
Some password managers already do this and I personally think its a nice feature. Though I often generate new emails and passwords for sites on the spot so this feature isn't of much use to me.