Because biometric authentication is a joke in the security industry?
Biometrics are fine to identify someone. Biometrics, being public data, is not acceptable for authentication nor authorisation.
To use another example:
You get to border control, and present your passport. The agent ensuring that the description in the passport matches the person standing in front of him/her, that is identification. The agent verifying that your passport is genuine and valid, that is authentication. The agent giving you access to a country based on the laws and arrangements between those two countries, that is authorisation.
Anything that can be copied/stolen with a good enough picture or forgotten glass/mug is not good enough for authentication/authorisation.
Biometrics are fine to identify someone. Biometrics, being public data, is not acceptable for authentication nor authorisation.
To use another example:
You get to border control, and present your passport. The agent ensuring that the description in the passport matches the person standing in front of him/her, that is identification. The agent verifying that your passport is genuine and valid, that is authentication. The agent giving you access to a country based on the laws and arrangements between those two countries, that is authorisation.
Anything that can be copied/stolen with a good enough picture or forgotten glass/mug is not good enough for authentication/authorisation.