Also, I think he misconstrues the purpose of Touch ID. It's not meant to completely replace passwords.
There are three categories of authentication methods:
1. Something you know (password, combination, challenge responses).
2. Something you have (crypto token, phone, key).
3. Something you are (fingerprint, face, DNA, etc).
Methods can be combined for added security. All three have advantages and disadvantages. Passwords are typically chosen by users, making them weak. Good crypto tokens are hard to copy, but loss or theft can mean getting locked-out. Biometrics are convenient, but can't be revoked. Also, some activities can make them hard to read.[1]
Apple uses all three authentication methods in the iPhone. Touch ID is for basic access. The passcode is for admin-level functionality like erasing or restoring the device. Lastly, physical access to the phone is required to decrypt important data such as Apple Pay's Device Access Numbers. This gives typical, non-technical users a sane combination of security and convenience. If thieves and scammers start copying fingerprints, Apple will change their auth mechanisms.
1. I love Touch ID, but it takes a while to work again after I rock climb or lift weights.