"No, email is not a secure medium. It was never designed to be one. It’s susceptible to Man In The Middle (MITM) attacks and a slew of other issues. Users might also have their email accounts abused or hacked into (how many people do you know who have left their GMail logged in on a public computer?). And what about if their email provider gets hacked or their backups stolen?"
Mozilla should know that email is not an adequate medium for one-time password delivery.
They are replacing strong authentication (2 factors) with its second factor alone.
[1] http://plaintextoffenders.com/faq/devs [2] https://news.ycombinator.com/item?id=7943365