How many cookies did you eat today?

We opened one article on each of 46 websites, read it to the bottom without clicking anything, and kept a record of every cookie it left behind, and then we went back to the man who invented them in 1994.

Behind this headline: all 11,366 of them, name by name. Orange ones were set by a company other than the site we opened.

An hour's worth of coding

Netscape Navigator in its box, at the Computer History Museum.
Netscape Navigator in its box, at the Computer History Museum. Marcin Wichary from San Francisco, Calif., CC BY 2.0
Navigator 1.1 for the Mac,
Navigator 1.1 for the Mac, "US and Canada only, not for export". Kevin van Haaren, CC BY-SA 4.0

In the summer of 1994 Lou Montulli was 23 and an engineer at Netscape, and the web had no memory, because, as he put it to NPR, the web server would completely forget every one of its visitors every single time they connected, which made something as ordinary as a shopping cart impossible.

Colleagues wanted to give every browser one permanent ID, and he refused, because, as he wrote years later, the unique identifier could be used to track a user at every website. He gave each site its own small note that only that site could read back, named it after the "magic cookie", a term he had picked up in a college operating-systems course, and wrote it in maybe an hour's worth of coding.

Montulli's own blog, May 2013:
Montulli's own blog, May 2013: "The reasoning behind Web Cookies", where he explains why he refused a single ID for every browser. Screenshot by sheets.works, 9 October 2026, source
Netscape's cookie specification,
Netscape's cookie specification, "Preliminary Specification, use with caution", as the Internet Archive first saw it in October 1996. Netscape Communications, Own screenshot of an archived page, editorial use
Netscape Navigator 2, by then the browser most people used to see the web, and the one that carried cookies to them.
Netscape Navigator 2, by then the browser most people used to see the web, and the one that carried cookies to them. Indolering, CC0

"We had specifically designed this not to be possible. This was a big violation of the spirit of cookies."Montulli, on reading in CNET that ad networks were following people from site to site. NPR Planet Money, 18 November 2022.

Within two years the advertising companies had found the way round, by putting the same ad, and the same cookie, on thousands of different sites, and at 25 Montulli could have switched it off, because Netscape had about 80 percent of the browsers in use. He chose not to, saying it would kill about 90% of the revenue going to the web at that time, a figure he gives from memory.

DoubleClick's homepage in December 1997, the ad company that turned the cookie into a way of following people across sites.
DoubleClick's homepage in December 1997, the ad company that turned the cookie into a way of following people across sites. DoubleClick Inc., Own screenshot of an archived page, editorial use

In 1997 he co-wrote the first standard for cookies, RFC 2109, which told every browser to refuse cookies from sites you had not chosen to visit, and every browser maker shipped them anyway, so that his co-author David Kristol wrote in 2001, Evidently we reasoned wrong. Vendors have steadfastly supported the advertising industry.

Section 8.3 of RFC 2109, February 1997, the paragraph that told browsers to stop cookies being shared between sites. Browsers shipped without it.
Section 8.3 of RFC 2109, February 1997, the paragraph that told browsers to stop cookies being shared between sites. Browsers shipped without it. Screenshot by sheets.works, 9 October 2026, source

Montulli once bought gutter protection, after which the ads for gutter protection followed him around the web for seemingly forever, and when NPR asked how that felt, he said, Yeah, I do feel somewhat responsible for the state of the world.

One news story, 618 cookies

On 9 October we opened one AP News story, about eviction protests in Spain, in a fresh copy of Chrome on an ordinary connection in India. A banner came up asking whether we agreed to share our data with AP's 630 partners, and we did not answer it, we just read the story to the bottom, and by the last paragraph our browser was already holding 618 cookies.

Each square is one cookie left by the AP News article. White: set by AP itself (32). Orange: set by another company (586). Hover or tap a square for its name.

Twelve of the 618, the way your browser lists them

nameset bystays forvalue
__cf_obAP Newsuntil you close the browsera random ID
kameleoonVisitorCodeAP News1 yeara random ID
RegWallAB01AP Newsuntil you close the browsera random ID
TDIDThe Trade Desk1 yeara random ID
UIDcomScore390 daysa random ID
_li_ssZeta Global30 daysa random ID
syncTripleLift30 daysa random ID
_fsuidFreestar400 daysa random ID
stx_user_idEquativ30 daysa random ID
cnx_userIdJWP Connatix14 daysa random ID
csuuidPrimis25 daysa random ID
avnguidAdvangelists1 yeara random ID
From the AP News visit. In Chrome you can see the same list for any site under DevTools, Application, Cookies. We stored the shape of each value, never the value itself.

AP set 32 of them itself. The other 586 were set by 162 other companies whose code came in with the ads and the video player, and a cookie from one company riding along on somebody else's page is the case Montulli wrote his design to rule out.

Who left them

Cookies per company on the same article, the 20 biggest. A company is the domain that set the cookie, named where we could match it.

Most of the names at the top are ad-auction companies that a reader would never knowingly visit, nexx360.io with 53 cookies, AdaptMX with 36, then VerveGroup, NextMillennium and Comcast, and each of them is holding its own ID for this one browser so that it can recognise it the next time one of its ads loads, on any site.

How long they were set to stay

Lifetime each cookie asked for when it was set. Chrome caps every cookie at 400 days.

Some of them are meant to vanish when you close the browser, but most are not, and 26 asked to stay for 400 days, which is the longest Chrome allows any cookie to live, so if you read that story today they would still be in your browser next October.

AP News article, loaded once from India on 9 October 2026, fresh Chrome profile, no buttons clicked, cookies read from the browser's own store at the end of the visit.

Then we did it on 45 more websites

We repeated the same visit on news sites in the US, the UK and India, and on recipe, weather, reference and forum sites, one article each, nothing clicked, 46 articles in all. The typical article left about 260 cookies, close to nine in ten of them set by somebody other than the site, and across the whole run 305 different companies set at least one cookie from outside the site we had opened.

Cookies left by one article on each site

White: set by the site itself. Orange: set by another company. One article per site, loaded once from India, 8 and 9 October 2026. Bars marked with a dot showed a cookie banner.

The Indian news sites ran heavier than the rest, with a median of 336 cookies against 260 for everything else, led by Hindustan Times and Indian Express at 348 each and the Times of India at 336. At the bottom, on its own, is Hacker News, which left no cookies at all, followed by Craigslist with one and Wikipedia with 11, every one of them its own.

The same companies on every site

The same names kept coming back. A cookie from one company on 38 different websites is precisely what Montulli tried to make impossible, one ID that is recognised everywhere you go, and that is what the dots below show.

Which companies set cookies on which sites

Each row is a company that set a cookie as a third party, each dot a site where it did. The 16 companies found on the most sites. Hover a dot for the site.

How one company recognises you on two different sites

apnews.comthe story you chose to read ad slot, loaded fromadsrvr.org huffpost.com, a week lateranother ad slot, also fromadsrvr.org browser sends TDID = 7f3a… browser sends the same TDID = 7f3a… The Trade Desk (adsrvr.org) 7f3a… read a story on AP News7f3a… then read HuffPostone profile, no name needed
The browser sends a site's cookies back to it wherever it is loaded, including inside an ad on someone else's page. The Trade Desk, which sets the TDID cookie, set cookies on 37 of the 47 sites we opened. The ID shown is shortened and made up.

Google set cookies from outside on 38 of the 47 sites that loaded, The Trade Desk on 37, Adobe and LiveRamp on 36, and none of them was the site we had opened. On the typical article, ID-like values from those cookies were sent on to about 55 other domains while the page loaded, the cookie syncing that lets companies that never met you compare notes on you.

How two companies swap their names for you

Company Aknows you asA-71f2… loads an invisible image from B: b.example/sync?partner_uid=A-71f2… Company Balready knows you as B-c09e… writes down: A-71f2… = B-c09e…now they can trade notes on you
This is cookie syncing. On the typical article we opened, IDs from cookies went out inside request addresses to about 55 other domains. On AP News alone, nexx360.io passed IDs to a-mo.net 96 times in one visit. IDs shortened and made up.

What one cookie actually says

A cookie is only a short line of text, and the clearest way to see what it carries is to take one apart. Here is the example Meta prints in its own documentation for the _fbp cookie that its advertising pixel leaves behind.

fb.1.1596403881668.1116446470

fbWhose cookie it is, the same on every website, so Meta's code can find its own note on someone else's site.
1Which part of the website's address it was set on. Bookkeeping.
1596403881668The moment the pixel first saw this browser, in thousandths of a second since 1970: Sunday 2 August 2020, 21:31:21.668 UTC.
1116446470A random number. With the time, it makes this browser one of a kind to Meta, with no name anywhere in it.

Source: Meta for Developers, Conversions API parameters ("version.subdomainIndex.creationTime.randomnumber").

The whole mechanism: the site sends a cookie with the page, and the browser hands it back on every later visit.
The whole mechanism: the site sends a cookie with the page, and the browser hands it back on every later visit. Tizio, CC BY-SA 3.0

Google's own cookie policy shows how long the note is meant to last, and where you live decides it, because the IDE cookie it uses for advertising last[s] for 13 months in the European Economic Area, Switzerland and the United Kingdom and for 24 months everywhere else, which includes India, although Chrome now trims every cookie to 400 days.

The cookie that asked to live 58,700 years

A cookie names its own expiry date, and some ask for absurd ones. On the New York Post, two cookies asked to be kept for about 58,700 years, TMZ and Fox News set one asking for 999 years, Allrecipes and People one for 68 years, and the Times of India a device ID for 49 years. In all, 1,192 cookies in our run asked to outlive the 400 days that Chrome allows, and Chrome stored every one of them for 400 days instead, without telling the site.

What some cookies asked for

Lifetime requested in the cookie's own Set-Cookie line or script, in years. Chrome stores no cookie longer than 400 days (1.1 years). Log scale.

Only 3 percent of the cookies we collected were the kind that disappears when you close the browser. The typical persistent one was set to last 93 days, and 90 percent carried the setting that lets them travel with requests to other sites.

What you can't see, even with the cookies gone

Montulli's defence of his decision was that cookies are at least visible, and that you can go up to your cookie settings and tell it to forget, and it will forget. The tracking that has grown up around them is harder to see.

Your browser gives away dozens of small facts every time a page asks, its screen size, its fonts, its graphics card, its time zone, and together they can work like a fingerprint, with no cookie needed: in a 2010 study by the Electronic Frontier Foundation 83.6 percent of browsers were unique, and in a later, larger study of two million browsers about a third were.

EFF's Cover Your Tracks, which tests how unique your own browser looks to a tracker.
EFF's Cover Your Tracks, which tests how unique your own browser looks to a tracker. Screenshot by sheets.works, 9 October 2026, source
A real browser fingerprint from the 2016 study by Laperdrix and colleagues: each line is a fact a page can read without asking.
A real browser fingerprint from the 2016 study by Laperdrix and colleagues: each line is a fact a page can read without asking. Laperdrix, Pierre, CC BY 4.0

IDs also travel inside links, as the fbclid and gclid tags added to links you click on Facebook and Google, and the pixel that Meta sells to websites turned up in 2022 on 33 of the top 100 hospital websites in the US, sending details of appointment bookings back to Meta, according to an investigation by The Markup.

What is left when you block them

Chrome has a switch to block third-party cookies, and we flipped it and opened the ten heaviest articles again. Cookies fell from a median of 379 to 46 per article, but the tracking cookies stored under the site's own name barely moved, because ad companies' scripts write them into the site's own jar, where they count as first-party.

Ten heaviest articles, normal against third-party cookies blocked

Median per article across AP News, HuffPost, BuzzFeed, USA Today, The Independent, TechCrunch, Hindustan Times, Business Insider, Indian Express and Fandom. Same day, same machine, Chrome's own "Block third-party cookies" setting.

Google's ad cookies survived on 9 of the 10 sites, alongside Google Analytics, Meta's _fbp and the shared IDs from LiveRamp, Lotame and Prebid, and the 141 third-party cookies that still got through were all of a kind Chrome lets through on purpose, partitioned so that each one only works on the site where it was set. The IDs still travelled too, just inside the addresses of requests instead of in cookies, with a median of about 25 IDs per article still sent to about 17 other domains with the switch on.

The cookie that was supposed to die

In January 2020 Google said Chrome would phase out third-party cookies within two years. It delayed that three times, turned them off for 1 percent of users in January 2024, said in July 2024 that it would let people choose instead, dropped even that choice in April 2025, and in October 2025 wound down most of the Privacy Sandbox tools it had built to replace them, citing low adoption.

Google's own picture of Chrome's Tracking Protection, December 2023, the 1 percent test that never went further.
Google's own picture of Chrome's Tracking Protection, December 2023, the 1 percent test that never went further. Google, Official Google blog image
Google, 22 July 2024:
Google, 22 July 2024: "Instead of deprecating third-party cookies". Screenshot by sheets.works, 9 October 2026, source
Google, 17 October 2025: Privacy Sandbox technologies
Google, 17 October 2025: Privacy Sandbox technologies "being phased out". Screenshot by sheets.works, 9 October 2026, source

Apple and Mozilla went the other way years earlier. Safari's Intelligent Tracking Prevention started cutting third-party cookies in 2017, and Firefox has kept each site's cookies in a separate jar for everyone since 2022, but Chrome has about 89 percent of browser use in India and still accepts third-party cookies by default.

Apple’s 2017 timeline for Intelligent Tracking Prevention.
Apple’s 2017 timeline for Intelligent Tracking Prevention. Apple Inc. / WebKit, Official WebKit blog image
Mozilla’s drawing of Total Cookie Protection: one jar per site.
Mozilla’s drawing of Total Cookie Protection: one jar per site. Mozilla, Official Mozilla blog image

An hour of code, thirty years on

Montulli wrote the cookie so that no one could follow you from one site to the next, kept the loophole open because he thought the young web needed the money, and co-wrote a standard telling browsers to close it that every browser ignored. On one ordinary news story in October 2026, 162 companies other than the publisher left a note in our browser, and the only site in our sample that left none at all was Hacker News.

How we measured all of this, with the raw data and the script, is in the notes below.

How we made this

We loaded 53 websites in Puppeteer with Chrome 146, one fresh browser profile for every page, from a home connection in India, on 8 and 9 October 2026. For each site we opened the homepage and one article, scrolled to the bottom, clicked no buttons, and read every cookie in the browser at the end. 47 homepages and 46 articles loaded; Daily Mail, Ars Technica, Reuters, The Economist, dictionary.com and Stack Overflow blocked our browser. We stored each cookie's name, the domain that set it, its size, lifetime and flags, and the shape of its value, but never the value itself. A cookie counts as a tracker when its domain is on EasyList or EasyPrivacy or a known tracking script wrote it; companies come from the Disconnect entity list where it knows the domain. The ten heaviest articles were loaded again with Chrome's own "Block third-party cookies" setting on. One run, one place, one day: counts move by tens of percent between loads because the ad auctions differ. For a bigger, regular count, CookieTosser scans 2,450 popular sites every month from Germany, before anyone clicks consent; ours is smaller and different in three ways: it was run from India, it reads every cookie after a full read of one article rather than the homepage, and it repeats the heaviest pages with third-party cookies blocked.

Pictures are credited under each one. Found a mistake? Write to akash@sheets.works.