Maybe 3 decades ago people had excuses, but the latest decade of cookie abuses have been designed by people who not only knew better but who took that better world into account as they buried it away from the general public. The fact that half a million developers think CORS is a server security measure isn't an accident.