We're using authentication in our Firebase app and it works wonderfully. Although all data is visible on the Firebase backend, we simply put pointer ids in Firebase, so no identifying data is publicly visible.
Care to elaborate? Firebase's FAQ seems to suggest that they're still working on a solution.
I believe they are working on a fully documented and stable auth solution; we're running something custom for now. Our whole Firebase namespace is read-only, so all our writing happens with a private key from our server. I think when the Firebase admin panel has more protection we can store more sensitive/identifiable data in there.
What level of control do you have for authentication? I didn't see much info on this on the website.
Write control was most important for us; all the readable data are simply id's to our internal DB