Why couldn't a web site have stolen his credentials in the same way?
And a bunch of other potential signals that would be missing in a native app.
It's not foolproof but it's a step forward.