With RSA private keys, users don't see or manipulate them directly (usually). With a private-key based security system, most users would go "Huh? what's a private key?" if you asked them to send it.
With biometrics, you can't send them over a phone or over the internet.
Social engineering will always be a problem, but passwords are far easier to obtain with social engineering. Biometrics and so on reduce the number of attack vectors.