To play devil's advocate: If Samsung had just stored it in plaintext, as you suggested they might as well do, then the title of the article would've been along the lines of "Samsung security FAIL! Stores your PIN code in plaintext, doesn't even try to obfuscate it."