Currently the only way to turn off the warning for insecure passwords (signon.management.page.vulnerable-passwords.enabled) is via about:config, we should allow users to do this is via about:logins or some other setting page to provide a more user friendly way to change the setting.