RE: Amnesty International's "Mutant Font"

Nice catch Nick,

For accessibility one would also want stay away from CAPTCHAS (as they stand today) as part of the solution, and perhaps rely on multiple biometric options. But biometrics wouldn’t fit the model where the user wants to avoid being indexed.

So what you suggest: some other evidence of interactive human participation to limit access to resources will have to be used.

* katie *
Katie Haritos-Shea 
Senior Accessibility SME (WCAG/Section 508/ADA/AODA)
Cell: 703-371-5545 | | Oakton, VA | LinkedIn Profile | Office: 703-371-5545

-----Original Message-----
From: Nicholas Doty [] 
Sent: Thursday, April 2, 2015 7:09 PM
To: Joseph Lorenzo Hall
Cc: public-privacy (W3C mailing list)
Subject: Re: Amnesty International's "Mutant Font"

On a brief review, it seems worrisome, although I like the idea of exploring alternative forms of obfuscation.

Does it give a false sense of security? Possibly. The obfuscation appears to be a simple substitution cipher, and if a bot wanted to translate back to the original text, it could: use the site's form itself to translate an alphabet and get the current substitutions; or download the corresponding font and use OCR; or run a simple cryptanalysis attack (maybe 50 or so characters would be required). The description of the project notes that the goal is just to "hinder", which is true in at least some sense: an attacker would have to write some code to follow one of those steps.

However, the main effect seems to be inhibiting accessibility, which would be relatively effective. No one with limited vision using a screenreader would be able to read your obfuscated text. :(

Finally, embedding the obfuscated text requires that the visitor load a font file and an image from the and (the latter over HTTP), which has its own privacy implications for your readers.

I would be curious to know whether there's an interest in using captchas or some other evidence of interactive human participation to limit access to resources online: for example, people who want to post content without its being indexed (and aren't satisfied with compliance with robots.txt).


A sample of the generated HTML and substituted text for "abcdefghijklmnopqrstuvwxyz" (at least with today's code):

<style type="text/css">
@font-face {font-family: 'Fonte_Mutante_4';font-style: normal;src: url('') format('truetype')}
.fonte_mutante_4 {
font-family: Fonte_Mutante_4;
letter-spacing: 1px;}

<p class="fonte_mutante_4">
    <a href="" target="_blank"><img src="" class="img-hd"></a> </p>

> On Apr 2, 2015, at 7:39 AM, Joseph Lorenzo Hall <> wrote:
> press story: 
> -promises-to-protect-your-privacy-online
> At first I thought this might be a way to thwart font-based active 
> fingerprinting to make your font list dynamic in your UA... but it 
> appears to be a way to write content online in an obfuscated way (for
> machines) that is still readable (for humans).
> :/ (not sure if it's an "April Fool's Day" joke... didn't try to use 
> it)

Received on Friday, 3 April 2015 13:13:01 UTC