do not forget though that advertisers and other sites can now track visits without their necessarily storing anything on the user's equipment, eg through IP address, through your browser's fingerprint aka Client-less Device Identification (CDI) (and see further this blog, UPDATE - and this WSJ article), so browser providers should also be ensuring that their browsers do not send anything more than t