But it won't work if your eyes are closed, or not looking at the screen. All it takes is 5 fails, and then your face is no longer an authentication token.
I haven't seen anything that explains what constitutes a failure. It seems plausible no eye contact wouldn't constitute a failure. It also seems plausible it would, but they may have to be more relaxed about what constitutes an "attempt" as looking at the phone is less definite than placing a finger on the sensor.