Were they wrong though? I'd wager far more credit cards have been stolen via the internet than by eavesdropping?
By contrast I refuse to send my credit card number in an email or post it on a non-SSL site.
Guess which way I’ve only ever had my credit card number stolen?