I'm upvoting this because you are correct that the GDPR about much more than just cookies, but I disagree with the (perceived?) negativity around how the regulation is vague.
It's designed to be vague because it covers intent and outcomes more than specific technical means of achieving them. This ensures the law doesn't need updating every time there's some new variant of local storage, new browser fingerprinting vector, etc and also to prevent offenders from trivially working around it using a technicality.
Similarly, enforcement will also be much more about intent and outcomes than any specific technical means (well that's the theory - in practice neither is being enforced right now). Nobody will enforce it based on some technicalities, they'll enforce it based on outcomes - if you collect personal data and use it to track a user without an appropriate legal basis (in this case, it should usually be consent), you'll be in trouble regardless of whether you use a cookie, a browser fingerprint, or even just save whatever search queries they type and use that as a way to reidentify them. Conversely, nobody is going to go after you if you set a session cookie to persist a login or shopping cart.