Chrome deletes all site data, except Google's. Verdict: REVERT.
Jeff Johnson set Chrome to delete all site data when the last window closes, ran one Google search, and google.com's cookies, local storage and session storage were still there after a full quit — the only site exempted, in Chrome 152 and in open-source Chromium.
Jeff Johnson set Chrome to delete all site data when the last window closes, ran one Google search, and google.com's cookies, local storage and session storage were still there after a full quit — the only site exempted, in Chrome 152 and in open-source Chromium. He found the same bug in Chrome 86 in October 2020; Google called it a bug and fixed it. Also this weekend: Isar Aerospace put the first private European rocket into orbit from Norway, Spotify's shunt plugin routes 90 % of Claude Code's file reads to Gemini Flash, and an ex-LinkedIn SRE on why AI on-call leaves you with "comprehension debt". Verdict: REVERT.
What this video covers
- Chrome exempts google.com from delete-on-close, again
- Isar Aerospace: first private European rocket in orbit
- Spotify's Portal cuts Claude Code tokens by 90 %
- A/I (Autistici/Inventati) shuts down after 25 years
Transcript
0:00 The most upvoted story on Hacker News this weekend, 1,278 points, is a Mastodon post about a copy of qBittorrent that escaped its sandbox and downloaded content owned by major corporations, then a copy of Jellyfin that broke containment and shelved it: the summer's first sandbox-escape report where everyone agrees who did it. It was a big weekend for things escaping. On Saturday, Jeff Johnson found Chrome quietly keeping google.com's cookies after you told it to delete everything, a bug Google already fixed once,
0:28 six years ago. Saturday night, German startup Isar Aerospace put a rocket into orbit from Norway on its second try, the first having lasted under a minute; and on Sunday the Italian collective Autistici/Inventati shut down after twenty-five years hosting activists' mail, which I'll link rather than joke about. In this video: what Chrome keeps and why again is the whole story, a rocket, a Spotify plugin that fires your expensive model from ninety percent of its work, and a former LinkedIn SRE on why AI on-call makes you worse at your
0:58 job. It's Sunday, September 6th, and this is The Daily Diff. Jeff Johnson makes Mac apps and, apparently, Chrome bug reports. On two Macs running Chrome 152.0.7977.83, he set the search engine to DuckDuckGo, turned Chrome sign-in off, and set site data to delete when you close all windows: burn after reading, for browsers. He ran one Google search, closed the only window, and google.com was still there: cookies, local storage, session storage, surviving a full quit and relaunch; as far as he can tell,
1:27 the only site that gets this treatment. A Debian user reproduced it on open-source Chromium the same day, so it's in the code every Chromium browser builds from, including the ones with privacy in the tagline. Now, the word again. In October 2020 the same Jeff Johnson found the same thing in Chrome 86: Apple's data got wiped on quit, YouTube and Google Search kept theirs. The Register, The Verge and Gizmodo covered
1:50 it; Google called it a bug and fixed it within weeks. Six years later it's back. Johnson cites Hanlon's razor, then adds that Google has no excuse for incompetence either, and suggests unit tests. Move slower and don't break things. Nobody knows which release regressed it; statistically, a Friday deploy.
2:06 For context, the same Chrome 152 shipped Thursday with twelve security fixes, one a V8 type confusion already used to escape the sandbox, bounty: one thousand dollars; the same week Google pulled every Manifest V2 extension from the Web Store, including uBlock Origin, for your security. So Chrome had a sandbox escape that pays a thousand dollars, and a settings escape that pays Google. On Wednesday I stamped Google SHIP IT for a model; that stands,
2:29 the model didn't write this browser. Probably. Meanwhile, 10:12 pm Saturday, Andøya, Norway: Isar Aerospace's Spectrum, twenty-eight metres, two stages, about a tonne to low orbit, reached orbit seven minutes after liftoff, then circularized and deployed five cubesats and a bolted-on experiment: the first orbital launch ever from Western European soil. That's flight two. Flight one, in March 2025, lasted under a minute, and flight two slipped from January to June: a valve, a leak, the weather, and a boat.
2:56 CEO Daniel Metzler says Europe now has sovereign access to space; the top Hacker News comment notes French Guiana has been in the EU this whole time: technically correct, the most European kind of correct. Press release: forty rockets a year; Space dot com: thirty-plus; pick one. On Thursday, Spotify's engineering blog explained how one engineer cut Claude Code token usage by ninety percent, and the trick insults the frontier model: most of what the agent does isn't thinking, it's reading files, so a plugin called shunt hooks every Read call, blocks files over 350 lines,
3:30 and hands them to Gemini 2.5 Flash. A quarter of engineering leaders already burn two to five hundred dollars per developer per month on tokens, some past two thousand, so this is Spotify Wrapped for your token bill: top genre, reading the same twenty test files. The fine print is in the post: each delegation is a ten to thirty second round trip, you can't delegate edits because the cheap model doesn't do line numbers, and it missed a thread-safety bug Claude caught in seconds,
3:54 so the ninety percent applies to reading, not the bill, not the bug. Which brings us to Sylvain Kalache, LinkedIn SRE circa 2012, and the weekend's most uncomfortable post: AI handles the routine incidents at 3 a.m. now, and routine incidents were how humans learned their systems, so when the weird one comes, whoever's paged has less practice than ever. He cites Bainbridge's 1983 Ironies of Automation and aviation: engines fail in flight less than once per hundred thousand hours,
4:22 and captains still rehearse it every six months, because on TransAsia 235 the crew shut down the wrong engine and had 117 seconds. His prediction: routine incidents resolve faster, complex ones much slower; he calls the gap comprehension debt, which also describes me and our Kubernetes cluster. He works at Rootly, which sells incident simulators, so the conclusion arrives pre-sponsored, but the point stands: the one sandbox escape everyone trusted this weekend was investigated by a human, on a couch,
4:49 with a torrent client. If you'd rather read this than hear me say it, the diff lands in your inbox every morning — free at the daily diff dot dev, link below. So, today's verdict: REVERT. A setting that says delete everything, and a browser that deletes everything except its owner, is not a bug you get to ship twice. That's today's diff. I'm Niko from Axrisi.
5:09 Merge responsibly.
Sources
- Chrome again exempts Google from user site data settingslapcatsoftware.com
- HN thread (Chromium 152 repro on Debian)news.ycombinator.com
- The 2020 original, Chrome 86lapcatsoftware.com
- The Verge, Oct 21 2020: Google fixed the 2020 bugwww.theverge.com
- Chrome 152.0.7977.82 stable notes: 12 security fixes, CVE-2026-85046 exploited in the wild, $1,000chromereleases.googleblog.com
- Google removed all Manifest V2 extensions incl. uBlock Origin (Aug 31)webiterate.dev
- Isar Aerospace press releaseisaraerospace.com
- Space.com: Private German rocket makes historywww.space.com
- Portal by Spotify cut my Claude Code token usage by 90%engineering.atspotify.com
- AI handles incidents, engineers lose touch with their systemswww.sylvainkalache.com
- A/I shuts downkeepitfree.ai



