Just because it is open source doesn't mean it is always the best.
I'm not too concerned. The fingerprint reader on my work-issued Thinkpad is absolutely fucking worthless and is never able to identify me, so it won't do an attacker much good if they manage to add ...