So, if I understand this article correctly, if a single terminal private key ever leaks, all the protections preventing any random passer-by from reading your biometric data go out the window[1].
You could partially mitigate such a weakness by including "not valid before" and "not valid after" timestamps in the certificates, which would have to be short-lived. Passports would then verify that the timestamp supplied by the terminal is in the correct range, as well as that it is greater than any previous timestamp this passport has ever recorded.