Earlier quoted context omitted.
The last bit here is a reach. For starters, Persona uses SSL, so it's encrypted. But more broadly, if you're going to use centralized, third-party authentication mechanism you could do far, far worse than Persona. I'd go so far as to say if your site is implementing its own authentication system, you could do yourself even more damage with a poor implementation. Your critique seems to missed an important part about P…
I know nothing about Persona. I have never used, and I have not read anything about it. But that much is clear to me: the communication between you and the Persona provider can happen very much over an encrypted channel, but the data in the Provider is not encrypted with a key which you only know. The Persona provider has the data in the open (except passwords, which are hashed) This whole fiasco has shown a weakness…
The only thing those in power would find out by looking at Mozilla's servers in charge with Persona authentication would be your freaking email address and that's it. This is by design.