Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them.
A house key is called a "key" though, so it must be a password, and thus must be secure! And biometrics are just usernames, so they're useless and insecure!
Sarcasm aside, my point is this. Even with the worst biometrics, your phone would be more secure than 99% of houses. And I don't see people complaining about the state of home security...
Ultimately, these username vs. password analogies are shallow understandings of security, and at best flawed.
Biometrics, passwords, house keys, secure dongles, etc. Those are _all_ keys. What they differ in is how reproducible they are, how easily they're lost, and how easily they're bypassed.
For example: Biometrics, when measured by devices with sufficient liveness tests, are robust against forgeries. That means they can't be stolen. This is in contrast to passwords and pincodes, which can be stolen by eyeballs, cameras, audio recording devices, etc. You can use FaceID or TouchID to unlock your phone in front of all the recording devices in the world, and yet still your biometric key won't be stolen.
See how that example comparison is far more interesting and enlightening than "biometrics are usernames, so they're pointless"?
* Of course, when I refer to household locks and keys, I mean your average household lock. There are, of course, premium locks with keys that can't be reproduced. But most houses have locks that you can sneeze on and open.