The further we take this analogy, the more strained it becomes.
Yes, it's natural to use a cookie to track a session; this is a mechanism invented for that purpose. It's much less natural to share this tracking information with third parties, especially along with a record of your purchases or other interesting actions.
But ad revenue is much harder to obtain without targeting and thus tracking. And a lot of places depend mostly on ad revenue.
This is another case of "buy now, pay later" pattern, stretched to "take for free now, pay in loss of your privacy later". In a funny enough way, many people don't value the information they get on many ad-supported sites as highly as the marketers paying to grab their attention, so simply compensating by adding a subscription or one-time payment to go ad-free sometimes does not even work; the more generic / "doom-scrollalbe" the content is, the worse it works.
It is not about cookies.
Are you a lawyer? Are you willing to assume the liability I may incur if I follow your advice?
Cookies that do not require consent [...] or authentication cookies (when users authenticate themselves on your web site to log in in order to check online services such as their bank account).
"""
https://europa.eu/youreurope/business/dealing-with-customers...
If you are worried about GDPR, by far the safest is to just not collect personal information.
A few things not allowed under GDPR:
1. Analytics
2. Third-party resources like fonts or JS libraries
3. CDNs
4. DDOS protection services
And I am sure I am missing many more. I am not a lawyer, but I worked with a few.
What you can’t do is trick the client to download something from a third-party source which then spy on the customer.
The real nirvana, IMO, would be better sandboxing between sites.
At a time a solution appeared with "do not track", and we ended up with the industry making sure it was as toothless as possible, opt-in, and google pushing hard to control the browser market.