I can only agree with the statement: “Unlike passwords, telling people not to reuse PINs is unrealistic. PINs should be used only for local authentication and designed to be safely reusable. Banks are wrong to use them on the Web.” The security premise of a PIN is that it is essentially a sender-constrained token—the place of use is an ATM, a cash card is also required, and it is therefore what is known as HoK. Naturally, it is no good to remove those constraints and use it as a bearer token.

The related thread on Twitter follows.

このX投稿は、静的引用データを取得できませんでした。

元投稿をXで見る

このX投稿は、静的引用データを取得できませんでした。

元投稿をXで見る

このX投稿は、静的引用データを取得できませんでした。

元投稿をXで見る

このX投稿は、静的引用データを取得できませんでした。

元投稿をXで見る

このX投稿は、静的引用データを取得できませんでした。

元投稿をXで見る

このX投稿は、静的引用データを取得できませんでした。

元投稿をXで見る