> For example: he says to remove the User-Agent header. Without that
https://www.dropbox.com/downloading wouldnt work (where they can give you the correct download and show you pictures of how to access/install it).
There is no good reason to do UA sniffing. That page could simply provide you one of 3 (or more) options to select.
> Furthermore, the Date header is very successfully used for caching operations in many cases.
Date headers are not useful for that purpose. Expiration would be based on the time of the UA, not the one given by a server.
> Moreover, it suggests problems that I see (such as the cookie kludge) but not a good replacement/solution for it.
The use of a session identifier, or to use client-side storage until it is needed. The session identifier is not the best solution, but it is a step towards a better system, I believe. Eventually I would like to see it removed.
> However, they cannot trust the clients and so have to resort to nasty things like hmac'ing the cookies and more easy to mess up security details.
You should never trust anything given to you from a client. If I send you a product list, that product list should be opaque ids. The session should be ephemeral and not matter anyway, so there is no reason for it to be signed.