Biometric passports with fingerprint data are common in many EU countries. The fingerprint is used to verify a person's identity, so in a way it's used as both a username and password.
Allowing the state to capture and store something very private to every individual is not without controversy. A few years ago, a German man called Michael Schwarz had his application for a passport rejected when he refused to have his fingerprints taken. He took the matter to the European Court of Justice (ECJ). In October 2013, the ECJ ruled in favour of fingerprinting for passports. The ECJ agreed that fingerprinting was a privacy intrusion but that this was outweighed by the need for security and protection against fraud. Strictly speaking, the fingerprint data should only be held in the passport, not in a central database.
Whether you agree or not with fingerprint capture will probably be influenced by how much you trust the authorities in your country. And of course, many countries collect fingerprints from visitors entering their country.
I trust that if I had enemies that needed my fingerprint for something, that could get it easily. I touch enough objects on a daily basis that the likelihood is extremely high. I mean, someone could simply lift them from my front door, or follow me waiting for me to drop a coffee cup in the trash.
EDIT: So does Kinect for Xbox one.
[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in
[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in
In my thinking about this problem from the IoT space lately, I've been thinking about servers assigning credentials to devices, rather than devices telling you their creds. Assign a UUID and let the device generate their password/key, and the pair gives you a multiplicatively large space.
Your notion is interesting. Anything that automates the client-side is good. People are terrible at managing a security contract 'by hand'
{edit} really, this superstitious notion that random numbers are 'not good enough' is embedded in our programmer culture. Folks continue to use lame solutions instead of just buying into the uuid-as-foolproof-identifier. It totally eliminates whole classes of problems and bugs. And you should be more concerned your computer will be hit by lightening, become self-ware and win the lottery 7 times, and molecularly reorganize into a teacup, before that uuid will be duplicated anywhere/anywhen.
Security is always done in layers, though, and while you're correct that it is extremely unlikely, the chance is nonzero. As such you have to prepare for that and design your system to be resilient to these types of things. In castle terms, you trust that no one will ever breach your wall, but that doesn't mean you don't have guards and an armory inside for the unlikely event it does.