We opened one article on each of 46 websites, read it to the bottom without clicking anything, and kept a record of every cookie it left behind, and then we went back to the man who invented them in 1994.
Behind this headline: all 11,366 of them, name by name. Orange ones were set by a company other than the site we opened.


In the summer of 1994 Lou Montulli was 23 and an engineer at Netscape, and the web had no memory, because, as he put it to NPR, the web server would completely forget every one of its visitors every single time they connected
, which made something as ordinary as a shopping cart impossible.
Colleagues wanted to give every browser one permanent ID, and he refused, because, as he wrote years later, the unique identifier could be used to track a user at every website
. He gave each site its own small note that only that site could read back, named it after the "magic cookie", a term he had picked up in a college operating-systems course, and wrote it in maybe an hour's worth of coding
.



"We had specifically designed this not to be possible. This was a big violation of the spirit of cookies."Montulli, on reading in CNET that ad networks were following people from site to site. NPR Planet Money, 18 November 2022.
Within two years the advertising companies had found the way round, by putting the same ad, and the same cookie, on thousands of different sites, and at 25 Montulli could have switched it off, because Netscape had about 80 percent of the browsers in use. He chose not to, saying it would kill about 90% of the revenue going to the web at that time
, a figure he gives from memory.

In 1997 he co-wrote the first standard for cookies, RFC 2109, which told every browser to refuse cookies from sites you had not chosen to visit, and every browser maker shipped them anyway, so that his co-author David Kristol wrote in 2001, Evidently we reasoned wrong. Vendors have steadfastly supported the advertising industry.

Montulli once bought gutter protection, after which the ads for gutter protection followed him around the web for seemingly forever
, and when NPR asked how that felt, he said, Yeah, I do feel somewhat responsible for the state of the world.
On 9 October we opened one AP News story, about eviction protests in Spain, in a fresh copy of Chrome on an ordinary connection in India. A banner came up asking whether we agreed to share our data with AP's 630 partners, and we did not answer it, we just read the story to the bottom, and by the last paragraph our browser was already holding 618 cookies.
Twelve of the 618, the way your browser lists them
| name | set by | stays for | value |
|---|---|---|---|
| __cf_ob | AP News | until you close the browser | a random ID |
| kameleoonVisitorCode | AP News | 1 year | a random ID |
| RegWallAB01 | AP News | until you close the browser | a random ID |
| TDID | The Trade Desk | 1 year | a random ID |
| UID | comScore | 390 days | a random ID |
| _li_ss | Zeta Global | 30 days | a random ID |
| sync | TripleLift | 30 days | a random ID |
| _fsuid | Freestar | 400 days | a random ID |
| stx_user_id | Equativ | 30 days | a random ID |
| cnx_userId | JWP Connatix | 14 days | a random ID |
| csuuid | Primis | 25 days | a random ID |
| avnguid | Advangelists | 1 year | a random ID |
AP set 32 of them itself. The other 586 were set by 162 other companies whose code came in with the ads and the video player, and a cookie from one company riding along on somebody else's page is the case Montulli wrote his design to rule out.
Who left them
Most of the names at the top are ad-auction companies that a reader would never knowingly visit, nexx360.io with 53 cookies, AdaptMX with 36, then VerveGroup, NextMillennium and Comcast, and each of them is holding its own ID for this one browser so that it can recognise it the next time one of its ads loads, on any site.
How long they were set to stay
Some of them are meant to vanish when you close the browser, but most are not, and 26 asked to stay for 400 days, which is the longest Chrome allows any cookie to live, so if you read that story today they would still be in your browser next October.
AP News article, loaded once from India on 9 October 2026, fresh Chrome profile, no buttons clicked, cookies read from the browser's own store at the end of the visit.
We repeated the same visit on news sites in the US, the UK and India, and on recipe, weather, reference and forum sites, one article each, nothing clicked, 46 articles in all. The typical article left about 260 cookies, close to nine in ten of them set by somebody other than the site, and across the whole run 305 different companies set at least one cookie from outside the site we had opened.
Cookies left by one article on each site
The Indian news sites ran heavier than the rest, with a median of 336 cookies against 260 for everything else, led by Hindustan Times and Indian Express at 348 each and the Times of India at 336. At the bottom, on its own, is Hacker News, which left no cookies at all, followed by Craigslist with one and Wikipedia with 11, every one of them its own.
The same names kept coming back. A cookie from one company on 38 different websites is precisely what Montulli tried to make impossible, one ID that is recognised everywhere you go, and that is what the dots below show.
Which companies set cookies on which sites
How one company recognises you on two different sites
Google set cookies from outside on 38 of the 47 sites that loaded, The Trade Desk on 37, Adobe and LiveRamp on 36, and none of them was the site we had opened. On the typical article, ID-like values from those cookies were sent on to about 55 other domains while the page loaded, the cookie syncing that lets companies that never met you compare notes on you.
How two companies swap their names for you
A cookie is only a short line of text, and the clearest way to see what it carries is to take one apart. Here is the example Meta prints in its own documentation for the _fbp cookie that its advertising pixel leaves behind.
fb.1.1596403881668.1116446470
Source: Meta for Developers, Conversions API parameters ("version.subdomainIndex.creationTime.randomnumber").

Google's own cookie policy shows how long the note is meant to last, and where you live decides it, because the IDE cookie it uses for advertising last[s] for 13 months in the European Economic Area, Switzerland and the United Kingdom
and for 24 months everywhere else
, which includes India, although Chrome now trims every cookie to 400 days.
A cookie names its own expiry date, and some ask for absurd ones. On the New York Post, two cookies asked to be kept for about 58,700 years, TMZ and Fox News set one asking for 999 years, Allrecipes and People one for 68 years, and the Times of India a device ID for 49 years. In all, 1,192 cookies in our run asked to outlive the 400 days that Chrome allows, and Chrome stored every one of them for 400 days instead, without telling the site.
What some cookies asked for
Only 3 percent of the cookies we collected were the kind that disappears when you close the browser. The typical persistent one was set to last 93 days, and 90 percent carried the setting that lets them travel with requests to other sites.
From India, only 8 of the 46 articles showed a cookie banner or a consent wall at all. The ones that did put a number on it: AP News asked about its 630 partners, El País listed 1,040 and Der Spiegel offered a choice between agreeing and paying for a subscription.


We never answered any of them. Only the Guardian and the Financial Times held their cookies back until we did, while AP News set its 618 and Fandom 359 with the question still sitting on the screen unanswered.

In Europe that difference between the two buttons has cost money. France's privacy regulator, the CNIL, fined Google €150 million and Facebook €60 million in December 2021 because refusing cookies took more clicks than accepting them, and in September 2025 it fined Google another €325 million, partly for making ad cookies harder to refuse than to accept.



India's data protection law, passed in 2023, does not mention cookies, and most of its consent rules do not start until May 2027, so a reader here has no legal right to a banner, and on most of the sites we opened, did not get one. The Advertising Standards Council of India reached a similar answer from the other side: its white paper Navigating Cookies, in January 2025, looked at the country's 50 most-visited sites and found only 3 that met basic consent requirements.
Chrome has a switch to block third-party cookies, and we flipped it and opened the ten heaviest articles again. Cookies fell from a median of 379 to 46 per article, but the tracking cookies stored under the site's own name barely moved, because ad companies' scripts write them into the site's own jar, where they count as first-party.
Ten heaviest articles, normal against third-party cookies blocked
Google's ad cookies survived on 9 of the 10 sites, alongside Google Analytics, Meta's _fbp and the shared IDs from LiveRamp, Lotame and Prebid, and the 141 third-party cookies that still got through were all of a kind Chrome lets through on purpose, partitioned so that each one only works on the site where it was set. The IDs still travelled too, just inside the addresses of requests instead of in cookies, with a median of about 25 IDs per article still sent to about 17 other domains with the switch on.
In January 2020 Google said Chrome would phase out third-party cookies within two years. It delayed that three times, turned them off for 1 percent of users in January 2024, said in July 2024 that it would let people choose instead, dropped even that choice in April 2025, and in October 2025 wound down most of the Privacy Sandbox tools it had built to replace them, citing low adoption.



Apple and Mozilla went the other way years earlier. Safari's Intelligent Tracking Prevention started cutting third-party cookies in 2017, and Firefox has kept each site's cookies in a separate jar for everyone since 2022, but Chrome has about 89 percent of browser use in India and still accepts third-party cookies by default.


Montulli wrote the cookie so that no one could follow you from one site to the next, kept the loophole open because he thought the young web needed the money, and co-wrote a standard telling browsers to close it that every browser ignored. On one ordinary news story in October 2026, 162 companies other than the publisher left a note in our browser, and the only site in our sample that left none at all was Hacker News.
How we measured all of this, with the raw data and the script, is in the notes below.
We loaded 53 websites in Puppeteer with Chrome 146, one fresh browser profile for every page, from a home connection in India, on 8 and 9 October 2026. For each site we opened the homepage and one article, scrolled to the bottom, clicked no buttons, and read every cookie in the browser at the end. 47 homepages and 46 articles loaded; Daily Mail, Ars Technica, Reuters, The Economist, dictionary.com and Stack Overflow blocked our browser. We stored each cookie's name, the domain that set it, its size, lifetime and flags, and the shape of its value, but never the value itself. A cookie counts as a tracker when its domain is on EasyList or EasyPrivacy or a known tracking script wrote it; companies come from the Disconnect entity list where it knows the domain. The ten heaviest articles were loaded again with Chrome's own "Block third-party cookies" setting on. One run, one place, one day: counts move by tens of percent between loads because the ad auctions differ. For a bigger, regular count, CookieTosser scans 2,450 popular sites every month from Germany, before anyone clicks consent; ours is smaller and different in three ways: it was run from India, it reads every cookie after a full read of one article rather than the homepage, and it repeats the heaviest pages with third-party cookies blocked.
Pictures are credited under each one. Found a mistake? Write to akash@sheets.works.