This is bad and insecure. Look at this:
https://m.youtube.com/watch?v=rERApU26PcASame thing with “pay with your face” they tried in China. They all are susceptible to replay attacks. It is garbage!
The only secure way to authorize actions is to have a device in your possession which you unlock with your password and/or biometrics — and use THAT device to sign interactive challenges or ZK-SNARKS.
The device could stores keys in a secure enclave, but regardless, the keys should never leave the device. The ability to export private keys (as with ethereum and bitcoin wallets) is insecure, too.
Look how 1password does it: local key plus master password. Far better than LastPass (master password only).
Also you should have notifications whenever a new device authenticates, or when you are trying to establish new recurring payments at a great rate than you would allow otherwise. Then you need to confirm from other devices.
That is the scheme that works universally and the further you depart from that, the more ridiculous hacks you get.