Some APIs (https://w3c.github.io/reporting/#network-leakage) have a threat model that requires considering passive network threats (https://www.w3.org/TR/security-privacy-questionnaire/#passive-network).
Should there be a question in the questionnaire that explicitly asks about this? I could imagine question 6 being expanded to: "Do the features in your specification introduce state that persists across browsing sessions and/or network changes?"
It seems to fit there as a question about data discard conditions.
Some APIs (https://w3c.github.io/reporting/#network-leakage) have a threat model that requires considering passive network threats (https://www.w3.org/TR/security-privacy-questionnaire/#passive-network).
Should there be a question in the questionnaire that explicitly asks about this? I could imagine question 6 being expanded to: "Do the features in your specification introduce state that persists across browsing sessions and/or network changes?"
It seems to fit there as a question about data discard conditions.