7 ms·
My proposal: 1. Browsers should ship with a set of fonts used just in the web browser that web designers can count on. Right now, there isn't a font I can coun
by Flimm 4y ago
My proposal:
1. Browsers should ship with a set of fonts used just in the web browser that web designers can count on. Right now, there isn't a font I can count on finding in Chrome on all platforms. This especially matters for non-English languages, where a different system font can lead to a website that looks very different.
2. Browsers should not load fonts installed in the operating system. It's a fingerprinting vulnerability. And it also causes issues where the system-installed font is unexpectedly different from platform to platform. For example, Arial is different across platforms, especially once you consider non-English languages.
- lelandfe 4y ago> Browsers should not load fonts installed in the operating system Already in the works, and some browsers don’t today (eg Safari). They permit the default system fonts (eg Helvetica) but nothing more from user space. In the future it will be a permission you grant a site: https://wicg.github.io/local-font-access/ https://wicg.github.io/local-font-access/ It’s a great move. The benefits of local fonts are negligible and the downsides are clearly enormous
- jonnycomputer 4y agoCrazy, in a way, that it wasn't already this way from the beginning.
- gfaster 4y agoimo it's more crazy that people thought of tracking users by using a font in the first place. The level of human ingenuity that has gone into spying on people is staggering.
- greyhair 4y agoFollow the money. It is always about the money. I was at a corporate security conference where one of the speakers stated that organized crime groups hire the top mathematicians and computer scientists from the top universities every year. They provide them with laboratories that you wish your company could afford.
- regentbowerbird 4y agoDid the speaker have a source for that claim beyond their own word? Surely there would be issues with such a scheme.
- enkrs 4y agoThe web and ideas back then were different. It was so cool to choose wingdings as a font, and make it <blink>. The web would not have evolved the way it is now if we hadn’t had the freedom back then.
- bagpuss 4y agomany years ago, too many fonts would cripple an average Windows install.
- layer8 4y agoThere weren’t any good permissibly-licenced fonts available back then, and browser fingerprinting only became a thing a decade or so later.
- lelandfe 4y agoWebKit/Safari gets dunked on a lot for being slow to implement features (sometimes rightfully so), but for many features, this is exactly why. Check out this long list of APIs they're purposefully dragging their feet on out of privacy concerns: https://webkit.org/tracking-prevention/#table-of-contents-toggle:~:text=Here%20are%20some%20examples%20of%20features%20we%20have%20decided%20to%20not%20yet%20implement%20due%20to%20fingerprinting%2C%20security%2C%20and%20other%20concerns%2C%20and%20where%20we%20do%20not%20yet%20see%20a%20path%20to%20resolving%20those%20concerns https://webkit.org/tracking-prevention/#table-of-contents-to...
- SahAssar 4y agoMany of those are gated behind permissions in the browsers that have implemented them, and safari could gate the rest too. Or they could collaborate with the working groups to reduce the fingerprinting hazard. Many other features that safari has been late with have basically no fingerprinting usefulness like web push.
- dingleberry420 4y agoI don't understand why they don't just ship a huge set of fonts by default. I'm probably missing some licensing bullshit, but look at Google Fonts and all the amazing fonts there. They're called open source fonts. Is there anything stopping firefox et al from just bundling them, or at least downloading them on-demand from a trusted server (not google)? It would be lovely if all web developers could just assume that the entirety of google fonts is at their disposal in a native way without having to resort to webfonts and the overhead that brings.
- pbhjpbhj 4y agoI'd be happy to have many more resources this way, use a hash and some sort of frecency -- but we've moved away from sharing resources across sites, unfortunately.
- layer8 4y agoThe problem is not shipping alternative fonts, but blocking access to the system fonts. For compatibility reasons, there needs to be a mechanism to still allow access for specific websites. That’s what the planned feature linked by the parent is for.
- d2wa 4y ago> I don't understand why they don't just ship a huge set of fonts by default. It takes a lot of work to draw a reasonable large set of all the Unicode characters for a given language. Time is money and fonts are ridiculously expensive. That being said, Firefox has funded a few fonts over the years but they don’t bundle them with the browser. Google has a huge collection but doesn’t bundle them either. It makes more sense with Google as it can collect user data from its WebFont as a service system.
- dingleberry420 4y agoRight, but the Google Fonts are open source so the work has already been done. https://developers.google.com/fonts/faq https://developers.google.com/fonts/faq
- josefx 4y ago> I can count on finding in Chrome Not like they have any ulterior motives to ensure your users have to ping Googles font service every time they open a page. None at all.
- pbhjpbhj 4y agoThe page should provide a hash, no need to ping a server, just a local cache lookup (like per-site cache schemes now) then a user-selected choice of downloading from the first-party, or an ordered list of third-parties.
- d2wa 4y agoBrowsers are all moving towards origin-isolation. So, even when you download a font from fonts.example.com from example.net; that downloaded font won’t be available to example.org. The local cache is, unfortunately, also an unintended source of fingerprinting and cross-origin communication.
- adrian_b 4y agoWhen for displaying Web pages a browser uses beautiful locally installed fonts instead of ugly widely available fonts, such as Arial, that is not a fingerprinting vulnerability. It becomes a fingerprinting vulnerability only after the browser (or a script with the permission of the browser) sends information to a 3rd party about which fonts are used on your computer to display text. The efforts to prevent vulnerabilities must focus on preventing undesirable communication between browsers/scripts and other parties, and not on how the Web pages are displayed, which should be done according to the user preferences.
- rpadovani 4y ago> The efforts to prevent vulnerabilities must focus on preventing undesirable communication between browsers/scripts and other parties, and not on how the Web pages are displayed, which should be done according to the user preferences. And how would you do so? Probably I lack in fantasy, but I really don't see a way to distinguish _necessary_ traffic from traffic that is useful only for exfiltrating data.
- ocdtrekkie 4y agoThe problem is you have to be willing to define a scope for what a web page should and shouldn't do. The largest developer of web browsers though happens to be obsessed with injecting support for crud like MIDI devices and serial ports to the web platform though, which makes it hard to define a good boundary for behavior.
- deleted 4y ago[deleted]
- jonnycomputer 4y agoUnpopular opinion: Arial is fine.
- NikolaNovak 4y agoI think I could happily live with say half a dozen fonts on the web (plus variations of bold/italic, if we want to count those as multipliers) for the rest of my life. Sarif, SansSarif, Mono, Weird - that's really my ability or care to tell fonts apart, when I'm there for the interesting article or funny video. But it's that tension: I, as a consumer, am happy with simplicity They, as producers, want branding and differentiation (not to mention tracking and all sorts of other things) Ultimately, and we mustn't forget this, they the producers are the ones investing effort they need a return on; and we the consumers are lousy when it comes to voting with our feet, dollars, scrolling thumbs and back buttons.
- danuker 4y agoGoogle pushes Noto, which is a requirement on Arch for Firefox. I ignore its updates, because they're large and quite frequent. https://github.com/archlinux/svntogit-packages/commits/packages/noto-fonts/trunk https://github.com/archlinux/svntogit-packages/commits/packa...
- btdmaster 4y agoIt is not a requirement. Packages that depend on it, like firefox, only depend on the virtual package ttf-font, which happens to be satisfied by noto-fonts: https://archlinux.org/packages/extra/x86_64/firefox/ https://archlinux.org/packages/extra/x86_64/firefox/. This means that you get to choose from ttf-liberation, ttf-bitstream-vera, ttf-droid, gnu-free-fonts, noto-fonts, ttf-croscore, ttf-ibm-plex, ttf-dejavu or even all the stuff in the AUR.
- danuker 4y agoWow, thanks. I was wrong. I will check out the other TTF fonts.
- p4bl0 4y agoNoto is also the default KDE font family.
- Waterluvian 4y agoIt’s amazing how fingerprinting is making the browser worse on every possible front and the best we can do is propose making it even worse.
- chii 4y agofingerprinting is a vulnerability that didn't exist previously (when browsers were designed). it's now difficult to remove that capability without affecting sites (display-wise, not fingerprinting-wise). reality sucks.
- account42 4y agoThe "vulnerability" has always existed, it was just not as widely exploited (or at least not known to be). As for how to fix it: When the cost for technical measures to ensure security gets too high we need legal measures to ensure a higher-trust society where such technical measures are not needed. We don't all live in locked down fortresses with bullet proof windows and filtered air and water supplies either even though technically that makes us more vulnerable.
- p4bl0 4y agoAgreed. In the meantime, there is a Firefox addon called Font Fingerprinting Defender that attempt to mitigate this attack: https://mybrowseraddon.com/font-defender.html https://mybrowseraddon.com/font-defender.html
- bgro 4y agoOn this point, I would like to put some of the major libraries (like jQuery) just wrapped into the browser and developers have to deal with it. Common graphics like the loading spinner could be included as well. Do we really need to be constantly redownloading all of this? It seems like a waste.