Even if the cookies would be properly encrypted, it still violates PCI DSS mandatory requirements - you aren't supposed to store or send a full credit card number unless necessary for an actual transaction.
They could do without a (full) CC number there. Ergo, it's a violation.
It's simple defense in depth, and does reduce the risks - say, if the encryption you thought was secure really isn't, etc.
They could do without a (full) CC number there. Ergo, it's a violation.
It's simple defense in depth, and does reduce the risks - say, if the encryption you thought was secure really isn't, etc.