I'm not saying that obfuscating the first 12 digits on a receipt solves the problem; just that it's a very minor adjustment that makes things more difficult for the attacker. But some organizations are still failing at even these most rudimentary steps.
But someone got the bright idea to attach other things to your credit card information, like your entire MacBook.
We need to burn down the entire concept of "security questions" and start over from scratch.
The UK may have a better protocol, but that doesn't change the fact that for a significant population, the number on the card is really anything but private. Certainly Apple should know this, being based in the US...
This is usually ok since credit card companies have the whole fraud thing figured out for the most part. It only becomes "not ok" when companies like Apple make them into something that absolutely needs to be secret.