Giving my finger and face prints to the browser, the software with the biggest attack surface in the world, connected to internet no less, feels off to me.
There have been some past complaints here about how Apple used to tie their fingerprint sensor into the secure element (third party folks couldn't substitute them). I actually liked that rule from a security standpoint, but obviously unpopular here. Same approach with faceid / touchID for the web.