Under "3.1.1 Retain Personalization Information":
The earlier version (20080522) had guidance on non-cookie methods of retaining information, e.g. "Information retention is possible by using cookies, as hidden information in content (e.g. forms, URL parameters, Javascript variables), in server-side databases, etc." The non-cookie methods are useful means to store information. As the section currently stands, users may be given the impression that cookies are the *only* recommended method of retaining state. Indeed, for the reasons noted about cookie limitations, other methods should be recommended as well. I welcome other input on methods of info retention, but to remove what has already been proposed does not improve the usefulness of the document.
The earlier version had guidance on the duration of retention, e.g. "The duration of retention should be matched to the type of application and typical user session profile, e.g. how often users typically access the application and how long they interact with it during each use." This may seem obvious to some, but the usability of an application can be significantly impacted by having to reenter information too often. So developers need to be thinking about the typical usage of their application, e.g. to establish a sense of the typical "session" length, and set their data retention design at least slightly longer than the typical session.
Best regards,
Bryan Sullivan | AT&T