I don't see how the deterministic nature of retinal scanning hashes means they couldn't be forged randomly. If there's secret sauce or a secret key in the algorithm that generates the hash then it's not an open platform. And given the stakes, it's only a matter of time until that gets cracked.