Something you are is the perfect form of authentication.
If you had a guard sitting at a door with only biometric information about the people they’re supposed to let in: faces, fingerprints, DNA samples, voice samples, etc. you could not fool them. Why? Because they can authenticate that the reading is coming from the actual person.
This is the revolution. If your phone can with good enough accuracy determine that it’s looking at a real alive attentive human face or a real finger then it’s game over. It’s an auth cred that can literally only be used by you, it can’t be copied, stolen, hacked, phished, and can be totally public while being useless to an attacker because they can’t mint a live human with real matching fingerprint.
If you think of biometric auth as “present a picture of your fingerprint” and not “present your actual finger” then of course you arrive at the conclusion that they’re useless as a credential.