Re: [csswg-drafts] [css-fonts] incorporate mitigations for font based fingerprinting (#4055)

> If I understand correctly, if browsers allow user set installed fonts as default fonts, it still could be utilize as fingerprinting 

Of course.

> Essentially, users may want to install and use fonts in web platform for various reasons, like a11y, business requirements, legal compliance, political position, aesthetics or just highlighting personality. It's a hard problem that how to make tradeoff between privacy and user rights of choice.

If users are given choice, we can't protect users who use the ability to make choices from being fingerprinted on those choices.

However, at present there's the problem that people who make no browser configuration changes still get fingerprinted on their non-Web uses of their computer. I think it's worthwhile to protect users who don't change browser font prefs from being fingerprinted on what fonts they've installed for other things that they do on their computer.

-- 
GitHub Notification of comment by hsivonen
Please view or discuss this issue at https://github.com/w3c/csswg-drafts/issues/4055#issuecomment-535902535 using your GitHub account

Received on Friday, 27 September 2019 11:33:22 UTC