Since the phone is covered in the password anyway, it would be interesting to see if it stands up to a gummi bear attack:
http://www.theregister.co.uk/2002/05/16/gummi_bears_defeat_f...
But I mean, a fingerprint is a physical thing which can be cloned, just like a key. And you also leave prints everywhere you go. It's not a silver bullet in authentication. All else being equal, passwords are safer against a determined attack, if we can assume correct usage.
In particular, tools automating (b) already exist: http://gizmodo.com/5896992/the-xry-cracking-tool-is-unimpres...