Hacker News new | ask | show | jobs
by camo 5100 days ago
So is javascript.

This is a ridiculous argument - there are no "good" reasons only a lot of FUD and font vendors who want this as a roundabout form of asset protection. The fonts are accessible by anyone who can use wget and can be copied and hosted anywhere else instead. Useless on all fronts, this just restricts the public web from end users.

Do not forget that the website must link to the asset in question. Why would they link to something they don't trust? Everyone trusts jQuery to not be malicious and everyone has links to cross-origin code running on their site. This is what makes the web a "web". Otherwise you would only be able to link with yourself.