Stop reusing PINs (unlike passwords) is an unrealistic idea. PINs should only be used for local authentication, and they should be allowed to be reused. It's the banks that use them on the web that are at fault.
I completely agree with the statement, "Stop reusing PINs (unlike passwords) is unrealistic. PINs should only be used for local authentication and should be reusable. The problem lies with banks that use them online." The fact that PINs are essentially Sender Constrained Tokens (requiring ATMs and cash cards as well, making them a so-called HoK) is a security issue…
