Biometrics are actually quite good if done correctly. Big caveat, I know, but just like a regular old password system, the raw data (whether the plain text password or biometric data) should never be stored directly on the authentication server. It should first be hashed in some form, and salted prior to doing so.
[ Hashing prevents any reverse engineering of the input data, and salting prevents the use of replaying the output on other sites, as well as mitigating rainbow table attacks. ]
Just like there are sites out there that are either lazy, ignorant, careless, or some combination of those that don't do password storage correctly, there might be biometric solutions that take similar bad practices. But if through regulation, standards, auditing, etc. we can ensure biometric solutions are using best practices, it could go a long way to solving the password problem.
A text without a context is a pretext.