I don't use it myself, but it's definitely worrying to see a secure option being potentially removed in favour of plaintext storage on servers outside the user's control.
I don't use it myself, but it's definitely worrying to see a secure option being potentially removed in favour of plaintext storage on servers outside the user's control.
When you want to authenticate, just have the client sign something with the private key. If you want to encrypt on the client, it can just do PGP-like encryption (encrypt data with random AES key, encrypt that key with public key, send all to the server).
That plus IIRC, RSA isn't deterministic even with the same seed. Not sure about generators for elliptic curve though.
https://wiki.mozilla.org/Identity/AttachedServices/KeyServer...
And RSA is deterministic.
> If you are a current Firefox Sync user, we’ll continue to sync your data between your devices.
So I guess the old option will still be maintained, at least during the testing phase.