It should be worth noting, taking someone's fingerprint and duplicating it is surprisingly easy. In fact, a duplicate print has been used to open door locks and even computer locks as the Mythbusters have shown :
http://www.h-online.com/newsticker/news/item/CCC-publishes-f...
Read up on more details and critique about TouchID: http://arstechnica.com/security/2013/09/fingerprints-as-pass...
It's important to note the scanner isn't an imaging sensor (I.E. camera) so touch and skin conductivity are still fair game.
It's also possible that it may not be a "password" in the conventional sense. Maybe the fingerprint only serves as part of the private key of a public/private key pair where only the public key is stored on the device itself and the private key must be generated each time with a scan of the finger.
This is all speculation, of course.
I suppose that is why we have people asking the questions.