And it's also illegal in EU. The GRPD imposes to have the choice to reject tracking cookies. And it must be easy to reject, not hidden somewhere or requiring one to manually delete the cookies with the browser mechanisms.
Yep, browsers should have per-domain cookie jars that get wiped when the all tabs/windows using that domain are closed.. and then a button not to wipe them on those few domains that you actually need them (to stay logged in).
But this is what you get when you have politicians dealing with technology.