<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://typophile.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Typophile - Securing font when used with font-face - Comments</title>
 <link>http://typophile.com/node/38534</link>
 <description>Comments for &quot;Securing font when used with font-face&quot;</description>
 <language>en</language>
<item>
 <title>You may also want to look at</title>
 <link>http://typophile.com/node/38534#comment-270343</link>
 <description>&lt;p&gt;You may also want to look at this thread with more information about ways to protect the fonts:&lt;br /&gt;
&lt;a href=&quot;http://www.typophile.com/node/43312&quot; title=&quot;http://www.typophile.com/node/43312&quot;&gt;http://www.typophile.com/node/43312&lt;/a&gt;&lt;/p&gt;
</description>
 <pubDate>Thu,  3 Apr 2008 11:34:48 -0700</pubDate>
 <dc:creator>Ralf Herrmann</dc:creator>
 <guid isPermaLink="false">comment 270343 at http://typophile.com</guid>
</item>
<item>
 <title>Thanks for this Ralf.
I</title>
 <link>http://typophile.com/node/38534#comment-270314</link>
 <description>&lt;p&gt;&lt;/cite&gt;&lt;br /&gt;
Thanks for this Ralf.&lt;/p&gt;
&lt;p&gt;I also was wondering if you could somehow secure a css file that contains information about a font to be safe on an EULA&amp;#8217;s side (e.g. &lt;cite&gt;&amp;#8220;Embedding of the XXX Font-Software into electronic documents or internet pages is only permitted in a secured read-only mode. The Licensee must ensure that recipients of electronic documents or internet pages cannot extract the XXX Font-Software from such documents or use the embedded XXX Font-Software for editing purposes or for the creation of new documents.&amp;#8221;&lt;/cite&gt;).&lt;/p&gt;
&lt;p&gt;Can anyone actually ensure that no one will eventually extract anything from even a super-protected file? I don&amp;#8217;t think so. Why such a statement then?&lt;/p&gt;
&lt;p&gt;Back to the topic, your solution seems enough &amp;#8220;protection&amp;#8221; for most users who browse websites. As stated many times before, one shouldn&amp;#8217;t really count in pirates who would steal/wouldn&amp;#8217;t buy anyway. The question is if font vendors see it as an enough secure embedding on the internet?&lt;/p&gt;
&lt;p&gt;________&lt;br /&gt;
&lt;a href=&quot;http://www.lenart.pl&quot;&gt;AL&lt;/a&gt; &lt;a href=&quot;http://www.lenart.pl/news&quot;&gt;▪&lt;/a&gt;&lt;a href=&quot;http://www.lenart.pl/work&quot;&gt;▪&lt;/a&gt;&lt;a href=&quot;http://www.lenart.pl/about&quot;&gt;▪&lt;/a&gt;&lt;a href=&quot;http://www.lenart.pl/contact&quot;&gt;▪&lt;/a&gt;&lt;/p&gt;
</description>
 <pubDate>Thu,  3 Apr 2008 09:51:15 -0700</pubDate>
 <dc:creator>aleksander</dc:creator>
 <guid isPermaLink="false">comment 270314 at http://typophile.com</guid>
</item>
<item>
 <title>I don’t see how Ralf’s</title>
 <link>http://typophile.com/node/38534#comment-268894</link>
 <description>&lt;p&gt;I don&amp;#8217;t see how Ralf&amp;#8217;s technique would add frustration to any &amp;#8220;honest customers&amp;#8221; or even honest web page viewers. &lt;/p&gt;
&lt;p&gt;The &amp;#8220;customer,&amp;#8221; it seems to me, would be the party putting the font on the server. The people viewing the page on the web which utilizes the font, who are not the people who licensed the font, are not prevented from seeing the font at all. If the technique required site visitors to have an account or type in a password or some other nonsense, I could see your point. &lt;/p&gt;
&lt;p&gt;In any case, what legitimate reason would anyone have to extract fonts from a cache (other than to demonstrate that there&amp;#8217;s a security hole)?&lt;/p&gt;
</description>
 <pubDate>Thu, 27 Mar 2008 17:22:57 -0700</pubDate>
 <dc:creator>Mark Simonson</dc:creator>
 <guid isPermaLink="false">comment 268894 at http://typophile.com</guid>
</item>
<item>
 <title>Well, if you know my stance</title>
 <link>http://typophile.com/node/38534#comment-268782</link>
 <description>&lt;p&gt;Well, if you know my stance on DRM, it&amp;#8217;s &amp;#8220;get rid of it completely.&amp;#8221;&lt;/p&gt;
&lt;p&gt;On the web there seems to be a strong urge to try and protect copyright concepts via technology...which always adds to the complexity/expense of the product, adds to the frustration of the honest customer, and is ultimately little to no deterrent to the person that doesn&amp;#8217;t care about copyright in the first place. ;o)&lt;/p&gt;
</description>
 <pubDate>Thu, 27 Mar 2008 10:51:26 -0700</pubDate>
 <dc:creator>aluminum</dc:creator>
 <guid isPermaLink="false">comment 268782 at http://typophile.com</guid>
</item>
<item>
 <title>Yea, it’s really easy to</title>
 <link>http://typophile.com/node/38534#comment-268756</link>
 <description>&lt;p&gt;&lt;cite&gt;Yea, it’s really easy to download the font: visit page in firefox&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;True. But it&amp;#8217;s an easy fix to prevent this in a future version. The point of this script is to have a system where a licensed website would get access to the font on the foundry&amp;#8217;s server, but access from other sites and direct downloads would be prevented. This can be done. I just don&amp;#8217;t have all the neccessary features and levels of protections in it yet.&lt;/p&gt;
&lt;p&gt;But 4thfebruary is also right. Once you access a licensed site the font will end up in your browser cache where it can extracted. And this will always be the case.&lt;br /&gt;
But still: Should we stop the iTunes music store because people know how to rip an DRM-protected song?&lt;/p&gt;
</description>
 <pubDate>Thu, 27 Mar 2008 09:45:46 -0700</pubDate>
 <dc:creator>Ralf Herrmann</dc:creator>
 <guid isPermaLink="false">comment 268756 at http://typophile.com</guid>
</item>
<item>
 <title>I just stumbled upon this</title>
 <link>http://typophile.com/node/38534#comment-268698</link>
 <description>&lt;p&gt;I just stumbled upon this thread again.&lt;/p&gt;
&lt;p&gt;Yea, it&amp;#8217;s really easy to download the font:&lt;/p&gt;
&lt;p&gt; - visit page in firefox&lt;br /&gt;
 - view CSS file&lt;br /&gt;
 - copy and past the URL to the font file&lt;br /&gt;
 - download the &amp;#8217;php&amp;#8217; file&lt;br /&gt;
 - change the extension to &amp;#8217;otf&amp;#8217;&lt;/p&gt;
&lt;p&gt;I now have Yanone Kaffeesatz Regular on my hard drive.&lt;/p&gt;
</description>
 <pubDate>Thu, 27 Mar 2008 07:02:19 -0700</pubDate>
 <dc:creator>aluminum</dc:creator>
 <guid isPermaLink="false">comment 268698 at http://typophile.com</guid>
</item>
<item>
 <title>Miguel Sousa
I’d think</title>
 <link>http://typophile.com/node/38534#comment-268682</link>
 <description>&lt;p&gt;Miguel Sousa&lt;/p&gt;
&lt;p&gt;&lt;cite&gt;I’d think that, if the resource(s) — font(s) in this case — are only loaded into memory, i.e. not saving any file(s) on the local system, it would make things pretty safe.&lt;cite&gt;&lt;/p&gt;
&lt;p&gt;Safari from Apple saves files into &amp;#8220;cache.db&amp;#8221; file (format SQLite3). with SQLiteExpert (no advertising), for example, technically prepared user, like me, can take everything.&lt;/p&gt;
</description>
 <pubDate>Thu, 27 Mar 2008 06:05:01 -0700</pubDate>
 <dc:creator>4thfebruary</dc:creator>
 <guid isPermaLink="false">comment 268682 at http://typophile.com</guid>
</item>
<item>
 <title>“I see, so browsers’</title>
 <link>http://typophile.com/node/38534#comment-236081</link>
 <description>&lt;p&gt;&amp;#8220;I see, so browsers’ developers are not of the hook yet, right?&amp;#8221;&lt;/p&gt;
&lt;p&gt;Copyright protection is not/should not be a TECHNICAL thing. It&amp;#8217;s a LEGAL thing. I see no reason for browser developers to hack the basic premise of the web in a weak attempt at forcing technical restrictions in the name of copyright protection.&lt;/p&gt;
</description>
 <pubDate>Mon, 29 Oct 2007 07:04:38 -0700</pubDate>
 <dc:creator>aluminum</dc:creator>
 <guid isPermaLink="false">comment 236081 at http://typophile.com</guid>
</item>
<item>
 <title>Nice work indeed!
&gt; So</title>
 <link>http://typophile.com/node/38534#comment-235988</link>
 <description>&lt;p&gt;Nice work indeed!&lt;/p&gt;
&lt;p&gt;&amp;gt; &lt;em&gt;So it’s absolutely safe? No! Everything you see in your browser window was already downloaded to you machine.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I see, so browsers&amp;#8217; developers are not of the hook yet, right?&lt;/p&gt;
&lt;p&gt;&amp;gt; &lt;em&gt;There is no real protection for anything that is on the web.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I&amp;#8217;d think that, if the resource(s) — font(s) in this case — are only loaded into memory, i.e. not saving any file(s) on the local system, it would make things pretty safe.&lt;/p&gt;
</description>
 <pubDate>Sun, 28 Oct 2007 15:23:09 -0700</pubDate>
 <dc:creator>Miguel Sousa</dc:creator>
 <guid isPermaLink="false">comment 235988 at http://typophile.com</guid>
</item>
<item>
 <title>Very nice, Ralf! From my</title>
 <link>http://typophile.com/node/38534#comment-235933</link>
 <description>&lt;p&gt;Very nice, Ralf! From my point of view, that’s heading in the right direction.&lt;/p&gt;
</description>
 <pubDate>Sun, 28 Oct 2007 11:16:13 -0700</pubDate>
 <dc:creator>Florian Hardwig</dc:creator>
 <guid isPermaLink="false">comment 235933 at http://typophile.com</guid>
</item>
<item>
 <title>Nice work Ralf. Thank you</title>
 <link>http://typophile.com/node/38534#comment-235932</link>
 <description>&lt;p&gt;Nice work Ralf. Thank you for posting this.&lt;/p&gt;
</description>
 <pubDate>Sun, 28 Oct 2007 11:13:16 -0700</pubDate>
 <dc:creator>canderson</dc:creator>
 <guid isPermaLink="false">comment 235932 at http://typophile.com</guid>
</item>
<item>
 <title>Securing font when used with font-face</title>
 <link>http://typophile.com/node/38534</link>
 <description>&quot;Font embedding&quot; is coming back to the web! The latest build of WebKit (used by Safari) has it, Opera is expected to follow. But the way they use it is by just linking a regular font file, which has to be placed somewhere on the internet, so everyone can download it.
Of course that doesn&#039;t go well with commercial fonts. 

So I set up a Proof of Concept to show a way to secure* a font used with the font-face command. Just download the &lt;a href=&quot;http://nightly.webkit.org/builds/overview/feature-branch&quot;&gt;latest version&lt;/a&gt; of Safari and open this page:
http://www.fonts.info/webfonts/

You should see two &quot;embedded&quot; fonts. The first is protected*, the second is not. Feel free to try to download Kaffeesatz. I won&#039;t explain how the protection works, but it uses several layers of protection. It is set up in a way, where the font would reside on the foundry&#039;s server and a remote, licensed website can use the font by adding a little snippet of code to its template. 

[img:Bild3_4933.jpg]

* So it&#039;s absolutely safe? No! Everything you see in your browser window was already downloaded to you machine. There is no real protection for anything that is on the web. 



</description>
 <comments>http://typophile.com/node/38534#comments</comments>
 <category domain="http://typophile.com/taxonomy/term/54">Blog</category>
 <pubDate>Sun, 28 Oct 2007 09:47:49 -0700</pubDate>
 <dc:creator>Ralf Herrmann</dc:creator>
 <guid isPermaLink="false">38534 at http://typophile.com</guid>
</item>
</channel>
</rss>
