Hacker News new | ask | show | jobs
by JoshTriplett 5104 days ago
Specifications can have bugs or deficiencies, and in those cases diverging from the specification can provide a net win. Also note that in this case the specification considers the cross-origin restrictions optional, not mandatory.

In this case, prohibiting the loading of fonts from other domains (unlike img, video, audio, CSS, script, etc) seems both unnecessary and harmful.

As I understand it, that bit of the specification exists for the sole purpose of mollifying large commercial font foundries, who consider themselves the only source of usable fonts, and who consider this particular point an existential threat.