Just remember that a 16bit Alpha numeric password that is stored on a server can take millions of years to brute force. Rainbow tables come into play and means it can be reduced to minutes but if the password is salted and stored correctly on a server then its basically non hackable. Banking for example would employ a front facing server for say the website but the actual user credentials of all their users would be on a separate server, where to access that server you would be using TPM and attestation it means only the banks own server can get in there. it would mean it makes it really hard for hackers to even get that far, this combined with a fail safe of 2fA on the users end means the system is basically vaulted.
When you know the game you know. The reason being is that they are going to push to the masses like we need to be doing all this biometrics BS. Really its just that they want mass surveillance.