Earlier quoted context omitted.
> It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet. Correct me if I'm wrong, but the biometric data never leaves the device.
It's also not stored on the device. Hashes, not fingerprints, are stored. You need the fingerprints themselves to fake out the hardware.
http://lukenotricks.blogspot.com/2009/04/on-entropy-of-finge...