As others have said, it’s quite good on privacy. For the truly paranoid, IIRC you can even self-host the sync server.
From the security perspective of privacy, do make sure to use a good password for the Mozilla account, the account password is also the encryption key for the E2E encryption.
You’re not mistaken, it is definitely possible with at least RSA, though, I would guess it may not always be possible. It also sounds like it’s still a bad idea unless you know all of the parameters used to generate the keys and can be sure what information is actually encoded in the keys.
That doesn’t mean the issue wasn’t/won’t be escalated. It might even mean it’s more likely since someone bothered to make a response macro for it, they presumably got more than one or two emails about it. So it’s probably more likely to make it on a “list of issues we saw this week/sprint/month/quarter”.