Cookies, in and of themselves, are not bad. Like any tool that can be misused, they're just being abused by a ton of really shitty people in an effort to try to enrich themselves at the expense of others. Cookies do solve a valid problem on the web, that being "How do we maintain 'state' from one page request to the next in a stateless protocol like HTTP(s)?"
Now we have a new (nearly impossible) problem to solve. "How do we prevent bad actors from abusing pretty much any feature of a public system which can possibly be abused, or reliably catch and punish the people who try?"
My reaction to this is always two fold; firstly cool tech, secondly horrifying invasion of privacy.
At {{job}} we did briefly consider rolling out fingerprint.com, but settled on ja3/ja4 at the CDN layer.
This is already illegal in the EU. The consent banners were never about cookies, they have always been about the tracking itself!
Cookies, in and of themselves, are not bad. Like any tool that can be misused, they're just being abused by a ton of really shitty people in an effort to try to enrich themselves at the expense of others. Cookies do solve a valid problem on the web, that being "How do we maintain 'state' from one page request to the next in a stateless protocol like HTTP(s)?"
Now we have a new (nearly impossible) problem to solve. "How do we prevent bad actors from abusing pretty much any feature of a public system which can possibly be abused, or reliably catch and punish the people who try?"