That doesn't seem like a big issue. Have browsers refuse all cookies by default, and let the server send headers that say "please allow these cookies, they're actually necessary". Browsers can either trust that list, or present it to the user and let them decide.