You are right, from the only point of view of the authentication, using a password gives you the same level of security as using one of its derivations (given a deterministic generation of the derivations and a password with same length and randomness of its derivations).
The mechanism that actually protects your credentials from being sniffed and used to get the first level of access to your account, is the industry standard SSL/TLS.
But even if someone discovers which is the derivation that you use to authenticate with the FileRock servers, they won't be able to know your password. And that means that the other derivations of your password (for example, the one used to protect the encryption keys for your data) are not disclosed as well. Therefore, even the people managing the FileRock servers will not know them, and they will not be able to access your encrypted data.
I hope this will solve your doubts.
PS: I see now that evv and notimetorelax also replied and they are correct.