with "free" I meant without additional effort for the developer.
When you set a cookie with a Set-Cookie header, the client will automatically send the cookie with all further requests.
When you put the session-ID somewhere in DOM storage, you have to manually amend all requests with that session-ID - either by appending it as a get parameter or, when you do nothing but AJAX, as an additional request header - but whatever you do, it's considerably more effort.
Also, looking at our logs, I see way more users with DOM storage disabled than with cookies disabled, but that might just be my user base.