Comment by jsheard

1 day ago

I would suggest not pushing your luck with webfonts though, because in that case you are distributing the actual copyrighted "code" of the font, not just the minimally protected shapes that it outputs. There are services which crawl the web actively looking for pirated webfonts on behalf of foundries (and their lawyers).

I had this happen to a client and even though they had both the web and print licenses they were hit with a 50k suite because the font file was malformed somehow. I'm not sure how it shook out but I hope they didn't pay a god damn cent.

How robust is that identification? Does it just look for file hashes or identical character shapes? I imagine it is trivial to repackage a font file to break the hash fingerprint.