Cookies allow storage of 4kb data in a file per single origin policy domain. They are slow to access and require an archaic API. At one point this made sense because it’s all we had.
Local storage features an amazingly primitive API, stores 5mb per domain, and is dramatically faster to access. Local storage is achieved universal support since IE8. From a storage perspective localStorage is a complete and superior replacement for cookies.
The only remaining difference is that cookies are artifacts separate from the browser. They can be sent in a an HTTP response without either a unique HTTP request and without appending that data to another artifact, such as hidden text in an HTML file. localStorage does not have that as it is meant to be local and thus would require JavaScript to write data from an HTTP response into storage. One extra step.
In practical terms all that means is that cookies can be written by a server application by developers who lack basic understanding of browser technologies. In software we call this kind of incompetence ”accepted practice”, but other industries call it negligence. I suspect if end users sued individual developers by name every time they were harmed or violated by bad software there would be less negligence in the world.