It would depend on the definition of cookie as well as the application context. When referring to browser or user accounts, obtaining them from random individuals would be associated with problems related to quality, security, and compliance. It is better to create your own source through your own users.