You're really misunderstanding the GDPR. Cookies are not mentioned anywhere in the law and it's actually really simple to understand:
1. You can do whatever you need to do to provide the service you're providing. (login cookies, sessions, store their email address, whatever).
2. If you want to process, store, and sell any other user data, you need to ask them first.
So for example if you want to send 100 advertising companies personal data about your users, you need to ask for consent and allow them to decline without restricting their access to you service.
What technology you use to track users is irrelevant, it can be fingerprinting or cookies or anything else.
The only reason why you think the law is bad is because companies are frantically trying to work around it, trying to interpret it in unintended ways to not impact their data tracking ways, and trying to make users hate the law instead of them.