The article is using "biometric authentication" to refer to WebAuthn-based authentication (which on lots of modern OSes can use biometrics to authenticate access to the keys used for WebAuthn).
It is indeed hard to steal WebAuthn keys out of modern secure mobile devices. It's not talking about stealing biometric data.
It is indeed hard to steal WebAuthn keys out of modern secure mobile devices. It's not talking about stealing biometric data.