JanH: Yes, I know about security through ignorance and this is not it.
This is not security per-se but just one method of detecting duplicate accounts used by trouble makers. It has been extremely effective so far and is a pity that it is likely to be less so now. Will it catch everyone? No, but it is useful non-the-less.
Site security is *not* based on an ignorant user-base but it is one thing having a system that can be circumvented if someon has the knowledge and another thing providing instructions.
This is in no way a vulnerability on the site but was a useful feature I'm sure you will agree - if I remember correctly I think you may have even suggested it at one point!
Forgive me but it is not me who continually bring up the subject of Kent and his forum - I only get involved in response to things posted over there. In fact, it almost seems to be the single consistent topic of conversation there - certainly the only one that get's any number of views. If anyone is obsessed over anything I think it is the other way round.
Yes, I could prevent the site from working for people who did not accept cookies but the idea is not to be a remote fortress but rather accessible - I do not want to limit who can use the site.
You suggest I should simply 'let things go' because 'Kent has no rubber bullets, only Nukes'.
a. Why the hell should I? I have tried being reasonable in the past ... no effect
b. That definitely sounds like a threat to me!