Pg 2 Gulf Times - UK Info Security Expert

Advises that ATM and credit card holders should change their pin codes quarterly as a primary defense against hackers.
OK...if he thinks so...but wouldn't it make more sense to just educate people that they should not share their pin codes with anyone since he indicates that people are sharing that information freely with others without giving it a second thought. Besides the fact that there should never be a reason to share one's pin with anyone, it is just plain stupid to do so. Sure, there are plenty of possibilities where a criminal can "steal" that information, but even those situations could be avoided with some basic education.
Also, banks and merchants should never store any of that information in clear text...meaning not encrypted. Of course we all know that most of the regional financial institutions don't follow best practices. Most of the receipts I get from merchants (at least up until recently) had my full credit card number printed plainly on them. Who the heck set these processes up and why do these institutions employ advisers and security professionals that at best can not follow simple and basic security standards and at worst are just oblivious to industry best practices and standards. Coupling that with poor technological security for their networks is just a recipe for disaster.
Speaking of information security education, wouldn't it be beneficial for all residents of Qatar if the newspapers would create a monthly column with tidbits of useful infosec information? It could be added to that computer information section I believe the Gulf Times prints each month.
Just my two cents.