People kept asking for cookieless tracking but with another way of identifying returning visitors that was always worse from a privacy standpoint. Cookies can be controlled by the client, anything stored on the server can not.
Honestly, cookies are pretty nice, it’s the law around this that sucks. Tricks that attempt to bypass the laws will surely only work for a limited time, at least I hope they will…
Cookies have built in browser behavior - they have limited scope, the browser lets you see them, they get cleared out regularly.
Abusing metadata is way sketchier.
- third-party cookie blocking/notification features in browsers
- review processes on ad networks checking for actual cookies rather than suspicious last-modified times