Yah, its finally here. Proper 2fa is now possible.
And now for the complaints.
Is it possible to have the PIN entry screen appear regardless of whether or not the fingerprint is valid?
Or in the alternative require that the PIN be provided before the fingerprint?
Because right now, a hostile party could force your finger onto the scanner and establish that your fingerprint is programmed into the device. Even without the PIN or access this can be very valuable information; if nothing else it can tie device ownership/access to you.
Ideally, I would like the fingerprint to serve as the enter key for the pin and the only result that is provided is the device unlocks or not. I have doubt's that this is possible without Google's access to the secure element though.