I agree that cookies being overwritten on every visit is the way for billing companies to go. Then there's no worry about possible cookie hacking or tricks by previous sites... and current sales are [basically] safe.
That said, I didn't see this mentioned elsewhere...
I know cookies are supposed to be off by default (according to RFC) and in the past Microsoft has had them turned on by default. No doubt because they just love following standards
However, I noticed that IE6 has cookies
quietly turned off by default. It even drove me nuts for a little while when all my scripts stopped working. This was becasue it even disables session cookies unless you take the trouble to specify otherwise.
With a good portion of Joe-Sick-Packers, I'd be surprised if they even bother to check this out. In other words, as more people get new computers and/or upgrade to IE6, I think the majority of the public will probably have cookies disabled.
I would hope the answer to this is no, but: Are there any billing companies out there who rely on cookies to credit sales?