This is pretty much where I’m at as well, on this issue. I only wish there were social security numbers contained in the breach so that we could stop considering them as personally identifiable info.
I agree with your meaning, and I think it goes beyond that. SSNs really are PII by definition; what we need to do is stop pretending that we can use any kind of PII in general as a form of authentication. Whether it's SSN, mother's maiden name, or any of these inane "security questions" that (thank goodness) finally seem to be receding from their peak, we need to move away from the fundamentally broken "tell me something about yourself that only you would know" model of authentication.
Agreed. Thank you for formalizing that ideal more coherently.