"So how do you respond to the fact fingerprints can be lifted (gummy fingers), and any security measure presented in Android seems to get bypassed routinely, even fingerprints and passwords/PINs? And that true paranoids run their banking runs on virtual machines?"

I'm not a true paranoid. I don't know of any open exploits with the fingerprint reader on Android or the phones I use. But it's still true that if you're targeted you can't do anything about it. Like locking your doors in your car and home, those measures can prevent casual or opportunistic crime, but you can't do shit if someone really wants to get that information. I do enough to prevent theft without everything becoming inconvenient and unworkable.

