6 ms·
WebAssembly in fonts doesn't sound very secure, coming from someone who is certified in cybersecurity and has spent years doing font stuff.
by stgiga 2y ago
WebAssembly in fonts doesn't sound very secure, coming from someone who is certified in cybersecurity and has spent years doing font stuff.
- lifthrasiir 2y agoBut probably much better than custom VM like TrueType bytecodes or embedded PostScript...
- ohmyiv 2y agoYes, that's the general consensus in the comments. It doesn't even sound safe to me and I'm not a full security pro. But OP did it as a PoC/for fun. It's okay to have fun still.
- lewispollard 2y agoIt's not what OP did that isn't safe, it's the mechanism that he used in HarfBuzz.
- ohmyiv 2y agoSorry for not disclosing everything that could go wrong, but you seemed to have missed my point while trying to be exact.
- lewispollard 2y agoAgain, it's not that anything the OP did is unsafe or could go wrong.
- ohmyiv 2y agoAgain, thanks for missing my point.
- lewispollard 2y agoI believe your point was "it's ok for OP to have fun with this project even if it's unsafe", but no one's saying that OP shouldn't have done this, since it's not what they've done that's unsafe. But if that wasn't your point, then OK, yeah.