The decision to serve the long chain (ending in the expired DST Root CA X3) was made, because the team believes that this will help the most users (those surfing to the site on their mobile devices). Other TLS implementations are generally more used by scripts, devops etc - not end users. Browsers in general will have no trouble with either chain, unless the (OS) trust store is out of date - in that case, neither chain works (except for systems that ignore the expiry of DST Root CA X3, e.g. Android).