Cookies, storage and tracking after third-party cookies
Cookies were the original way to recognise a returning browser, and for twenty years they were enough. The changes browsers have made to them explain why fingerprinting became interesting again.
First-party and third-party
A first-party cookie is set by the site in the address bar. It is how you stay logged in. A third-party cookie is set by a different domain whose content the page embedded, such as an advertising script, and it is readable by that domain on every site that embeds it. That second property is what made cross-site tracking trivial: one advertiser, one cookie, every site.
What changed
Safari began blocking third-party cookies by default in 2017 through Intelligent Tracking Prevention and tightened it repeatedly. Firefox followed with Enhanced Tracking Protection in 2019 and then Total Cookie Protection, which gives each site its own cookie jar so a third party's cookie on one site is invisible on another. Chromium introduced partitioned cookies (the Partitioned attribute, "CHIPS") so embedded content can keep state per top-level site, and spent several years announcing, delaying and finally stepping back from a blanket removal of third-party cookies, settling on user choice instead.
The practical result is that cross-site tracking by cookie is unreliable in Safari and Firefox and increasingly partitioned in Chromium. That is good for privacy and it pushed trackers toward the signals that do not need storage at all.
Other storage
localStorage, IndexedDB and the Cache API are first-party by nature; they belong to the origin that wrote them and are now partitioned by top-level site in every major browser, so they cannot be used as cross-site identifiers the way old third-party cookies could. ETag and cache-based tracking tricks exist but are fragile and widely mitigated.
Why fingerprinting fills the gap
A fingerprint needs no storage. It is recomputed from the browser's own properties on every visit, so clearing cookies does not reset it and partitioning does not isolate it. That is its appeal to trackers and its danger for anyone who assumed "clear site data" was a clean slate. The counter-measures are different too: not blocking storage, but reducing the diversity of what a page can read, which is what the user agent reduction, canvas noise and renderer masking are for.
What a diagnostic can show
A page can report whether cookies are enabled and whether the Do Not Track header is set (a signal almost no site honours, which is why browsers are removing it in favour of Global Privacy Control). It cannot read another site's cookies, and a trustworthy diagnostic sets none of its own. PowerScan runs with no cookies, no storage and no identifiers, which you can verify in the browser's developer tools: the storage panel for the site is empty after a scan.
What isolation means now
For anyone keeping accounts separate, cookies are the easy part: separate profiles have separate cookie jars. The hard part is the fingerprint, because two profiles on the same machine with the same browser share every hardware and rendering signal unless the browser changes them. That is the subject of the next article.