It's not (just) GDPR and TFA mentions that as soon as they move on from Cookies, ie point 2 on local storage:
"This buys you nothing. Article 5(3) of the ePrivacy Directive".
They clearly have a product to sell but the article seems balanced and offers a good list of commonly used/proposed techniques that are not quite compliant.
As you alluded, there're more lawful basis than consent, one of most common ones being technical necessity to mitigate abuse.