Respectfully, I’d like it if you were more nuanced in your opinion. What is seen as bad and wrong some, is perfectly fine for someone else. There is always a spectrum. A healthy mindset is treating security is a means to and end, not as the destination itself. You can use fingerprint authentication if it gets your threat model needs covered.
As a straight-on defense, these are some things that might curb your skepticism:
- Fingerprint authentication is an opt-in feature. So what you’re saying doesn’t make any sense for people who didn’t opt-in.
- You already said this part: “especially if no other factor is needed”. I think most of us here use 2FA on their Proton login because it fits the threat model of the average person interested in using Proton.