Re: [manifest] check against security/privacy questions (#305)

> Did you find the questionnaire helpful at all?

Extremely! it prompted me to rethink a bunch of stuff from different angles. As you can see from https://github.com/w3c/manifest/commit/63f8448274a393faf9e0e31874621116d01e1971, this yielded a lot of additional considerations originally missing from the document. 

>  Were any pieces simply nonsensical or unhelpful?

No. It was broad in its approach (in a good way, as it covered both declarative + imperative APIs as well as data formats) and the questions were clear. It was good to have the concrete examples too - as it made it easy to adapt to our spec. 

> Were any questions confusing?

Not particularly. Again, having the detailed text plus examples helped clarify what was being asked. I did read through them a few times, but more because I felt like I was doing a fun university exam than because it was complicated. The only one I think I had trouble answering was "expose cross-origin persistent state to the web?" 

I would encourage you to just quickly read over all the answers and see if you would have answered them  similarly. I know there are no "right" answers, but I think it would be super insightful to see if the reader (i.e., "me") can get into the right frame of mind to answer the questions - as you intended.

If you have time to review the answers, I would really like to hear how you would have answered some things differently. 

Thanks again for putting together the questionnaire! 

---
Reply to this email directly or view it on GitHub:
https://github.com/w3c/manifest/issues/305#issuecomment-72638983

Received on Tuesday, 3 February 2015 12:01:44 UTC