https://news.ycombinator.com/item?id=6934248 (cbc.ca) (66 comments and counting)
Another discussion:
https://news.ycombinator.com/item?id=6930258 (krebsonsecurity.com) (8 comments)
Other submissions:
https://news.ycombinator.com/item?id=6935413 (boingboing.net)
https://news.ycombinator.com/item?id=6935142 (cnn.com)
https://news.ycombinator.com/item?id=6934595 (target.com)
https://news.ycombinator.com/item?id=6934535 (securityweek.com)
https://news.ycombinator.com/item?id=6934216 (wsj.com)
https://news.ycombinator.com/item?id=6934038 (rt.com)
https://news.ycombinator.com/item?id=6933163 (chicagotribune.com)
https://news.ycombinator.com/item?id=6932782 (usatoday.com)
https://news.ycombinator.com/item?id=6932186 (arstechnica.com)
https://news.ycombinator.com/item?id=6932141 (theverge.com)
Edit: Also, PCI Compliance - personal information should not be stored unencrypted when at rest or when being transferred.