Hacker News new | ask | show | jobs
by toast0 404 days ago
> fixing the font does not help those that downloaded the font and won't get the new version. it also does not prevent malicious code from replacing the font on your machine with a version that has the ligature.

Fixing the code doesn't help users that downloaded code and don't get the new version either.

Malicious code that can replace a font can replace a lot more too.

1 comments

right, but a replacing a font is much easier than replacing a browser.