They could also add "invalid" headers of random length to push the cookie around making it difficult to find/inconsistent. Increasing the number of request/responses that the attacker would need to sniff on in order to break it.
The nice thing about this solution is that it could be done in the browser (e.g. Chrome) when it is connected to an RC4 site without any involvement of the server administrator.
It is also backwards compatible.
PS - Yes, I know, STOP USING IT - but in the real world if you told people today then they'll still be using it ten years from now...