Yes that's what I'm saying this could be used for. Browser generates a client-side key (or any kind of identifier, possibly derived from the site's TLS cert/domain or some other info) for the current browser/user/device/whatever and just offer that to every website as an extra header so that whoever wants to track you, can.