3 ms·
That's ridiculous, by this measure font ligatures are also contributing to fraud. Or, heck, even fonts themselves, who stops a font from displaying A as B?
by renerick 2y ago
That's ridiculous, by this measure font ligatures are also contributing to fraud. Or, heck, even fonts themselves, who stops a font from displaying A as B?
- worthless-trash 2y agoA secret division, crime fighters, working hard to keep fonts safe from misinformation, they work behind the screen, tirelessly, without thanks. We call them: The typeface police.
- kazinator 2y agoI suspect that your puerile mockery will come to a swift end when you discover you signed some contract that you read on the screen, but whose wording was altered by the printer.
- renerick 2y agoThis is not a realistic scenario whatsoever. Printers tend to print fonts pretty accurately to their on screen presentation. Even using contextual alternates, the perpetrator would have to change the font before printing. But if the perpetrator has this opportunity, they do need the font at all, they can just change the content. For example, CSS media queries that I mentioned in the other comment can show one paragraph on the screen and another when printing. You don't even need to put both in the HTML - CSS ::before and ::after will happily do that for you. It's also not very wise in general to not read the final printed version of the contract before signing
- worthless-trash 2y agoSir your first mistake was that you think that this was mockery.
- kazinator 2y agoNo, treating some letter sequences like fi and ffi so that the letters stick together in a certain way is not "by this measure". > who stops a font from displaying A as B It's noticeable; a B consistently occurs everywhere there is an A, wherever that font is used. You can't perpetrate an easter egg whereby a certain A is replaced. We could prepare a page where every glyph appears, and detect substitutions via OCR. With text replacement, we could look for a particular sentence, and change a word in it, without playing any games with glyphs at all. It will be undetectable in a document in which the target sentence doesn't occur. Anyway, we can't think about not using fonts. Fonts are necessary for rendering text. Fonts that substitute arbitrary text are not necessary. Just because I need fonts doesn't mean I need term-rewriting fonts. We don't have to accept one threat just because there is some inevitable minor threat. That's the Package Deal informal fallacy, or something along those lines.
- renerick 2y ago> No, treating some letter sequences like fi and ffi so that the letters stick together in a certain way is not "by this measure". Except ligatures are not limited to fi and ffi. They can be used to change appearance of any sequence of characters, including words. > It's noticeable; a B consistently occurs everywhere there is an A, wherever that font is used. I'm not talking about substituting a single letter. I'm talking about outright obfuscation of a entire texts. > You can't perpetrate an easter egg whereby a certain A is replaced. Quite the opposite, it is trivial to apply different fonts to different parts of text, so you can keep some parts of text normal, and some parts (like numbers and data) obfuscated. In HTML you may notice some abundance of <span>s, sure, but in PDF? Literally no way, unless you copy-paste everything and compare it. And this is not a hypothetical scenario or a 'minor threat'. Russian government used precisely this technique to obfuscate data in their online voters turn-out reports: (source in Russian, not found it reported in English) https://habr.com/ru/news/578846/ https://habr.com/ru/news/578846/. Have they used more subtle scrambling of only digits and not also mixing letters: who knows how long it would take for anybody to notice. From a technical perspective it's not so different from contextual alternates - both require custom made fonts. There are other ways to alter document presentation too. Especially in CSS, you can create pseudo-elements, not present in the original HTML, or hide parts of HTML, or use a media query which checks if the page is being printed or not! > We could prepare a page where every glyph appears, and detect substitutions via OCR. Why the extra step? Why not take the OCR of potentially compromised document and compare it with its raw content? It would detect every substitution, whether it's ligatures, alternates, media queries etc. Why not inspect the font file for defined alternates directly?
- kazinator 2y agoOK, I changed my mind about ligatures; out with the fi and ffi glued together and all of it. Concern with what text looks like is just emotional quaintness; it's not worth sacrificing security.