> This became a closely held secret in Facebook Ads leadership. We didn’t want to take any chance that word our this vulnerability could get back to Google.
Considering the tracking Google does with Chrome, I suspect they recognized the traffic still occurring over WebSQL and left it active for exactly this reason. It's highly unlikely that nobody at Google was able to recognize this. Alternatively, maybe Google didn't know about Facebook's reliance on it, but was aware of other services/corporations that still relied on it for some time, and waited until they had an alternative.
At the time this story takes place Chrome didn't have a way to collect web feature usage metrics broken down by site. It was aggregated across all sites to protect user privacy. That came years later with Rappor: https://www.chromium.org/developers/design-documents/rappor
WebSQL usage was too high at the time to remove though, so while the story is fun to read Chrome never would have actually turned it off.
[author] Hard to say. If Google leadership had heard of this vulnerability, right as they were launching Google+, there would at least have been a serious conversation about it. They spent $Bs to build Google+, changed their whole company structure to support it, and were losing hundreds of people to FB every month. I doubt bending one little rule about removing a deprecated technology would have bothered them too much.
Considering the tracking Google does with Chrome, I suspect they recognized the traffic still occurring over WebSQL and left it active for exactly this reason. It's highly unlikely that nobody at Google was able to recognize this. Alternatively, maybe Google didn't know about Facebook's reliance on it, but was aware of other services/corporations that still relied on it for some time, and waited until they had an alternative.