Steve have (likely correctly) predicted flood of biometrics in computer/online authentication. I am GenX old and raised in different country. There at University level computing we were trained that biometrics (or "who you are") should never be used for computing authentication because if broken, there is no way out. Biometrics was reserved for the final action of great consequences after the access and authentication were already done. Example: a room with the big red button. Access to the building and the room required authentication via documents and passwords and devices (multifactor) so that it is clear that a person has right to be there and activate the system. Biometrics would be used only to press big red button to confirm that the action is indeed by already authenticated person. Current trend hence, to me looks like emerging from tracking and tabulating people not from security side and should be fought against by experts. Particularly as this trend comes at the same time when emerging AI capabilities make it plausible to steal and abuse biometrics trivially. For me the best future would be two factor authentication with two "orthogonal" methods: passkeys AND password (latter one being as its definition -something you know, not something you have access to).

