The main concern I would have is someone spoofing the visual recognition system with something as crude as photographs, or something more advanced like a mask.
He states in that section, "Once it identifies the person, it checks a list to confirm I'm expecting that person, and if I am then it will let them in and tell me they're here." My first thought is someone could see if there's a friend/acquaintance who routinely visits, and then spoof their face with a mask. Let alone if the system automatically lets Zuckerberg in, then that's all that would be needed.