Biometric data is authentication. One looks at their mother and says "hi mom" not "what's the passcode?". Your issue, I think, is that you don't trust the tools on the phone to read faces or fingerprints well enough to detect fraudulent login attempts.
Factors of authentication:
* What you know - things like passwords online that other people shouldn't know
* What you have - Two-factor tokens, certs (kind of "know" but used to supplement "have") that other people shouldn't have
* What you are - Biometrics like finger, face, or eye that are unique and difficult to duplicate or trick (ideally)
So the question becomes which and how many factors to require, and when, depending on the risk model.
Unless you believe Apple is lying, that information is never sent to them. The hardware is designed such that, with TouchID at least, it's never even seen by the CPU on the phone.
If you do believe Apple is lying and is secretly phoning home with your personal information, then I think you'd have bigger problems than fingerprints; I would be more concerned about surveillance on everything you do with the phone.
What kind of analogy is that? I don't know what you were trying to say but you're way off on saying it. I think OP's point stands, biometrics: are not be relied upon for these matters.
What OP means is that at least theoretically faces contain enough information to uniquely and correctly identify someone, which is the reason why we identify someone by looking at their face. If iPhoneX was as good as a person in recognising faces then this discussion would be meaningless.
Factors of authentication:
* What you know - things like passwords online that other people shouldn't know
* What you have - Two-factor tokens, certs (kind of "know" but used to supplement "have") that other people shouldn't have
* What you are - Biometrics like finger, face, or eye that are unique and difficult to duplicate or trick (ideally)
So the question becomes which and how many factors to require, and when, depending on the risk model.