Re: [csswg-drafts] [css-fonts] incorporate mitigations for font based fingerprinting (#4055)

@hax would it suffice to have a browser setting (defaulting to off) to enable this?

(distinct from a per-page permission, for the reasons mentioned in https://github.com/w3c/csswg-drafts/issues/4055#issuecomment-505281057)?  This would be similar to the do-not-track setting defined in that standard, but defaulting to off instead of on.

@hax also, can you clarify what happens on these sites when you visit them in Safari, on a local install of OSX?  Do they work correctly in Safari b/c OSX installs a category of fonts that (for example) Windows doesn't?  Or that these sites don't support Safari / users w/ default fonts?

Would another option be to just have Microsoft systems include the common office fonts as the set of system fonts they expose (since the number of office users is likely large enough to preserve useful equivalence classes) 

-- 
GitHub Notification of comment by snyderp
Please view or discuss this issue at https://github.com/w3c/csswg-drafts/issues/4055#issuecomment-535855466 using your GitHub account

Received on Friday, 27 September 2019 08:57:05 UTC