I think you misunderstand Sampo's proposal. He's suggesting that the allowed domains be embedded in the font file itself.
Incidentally, that's essentially the same thing that EOT does. The difference between Sampo's proposal and EOT is that Sampo suggests using mechanisms provided by OTF/TTF to store the data rather than invent an entirely new container format.
The SSL based scheme strikes me as completely insane. PKI is a ton of work to maintain and this idea doesn't even address the crux of the issue, which is distributing full, proprietary OpenType / TrueType fonts.
Comments
I think you misunderstand Sampo's proposal. He's suggesting that the allowed domains be embedded in the font file itself.
Incidentally, that's essentially the same thing that EOT does. The difference between Sampo's proposal and EOT is that Sampo suggests using mechanisms provided by OTF/TTF to store the data rather than invent an entirely new container format.
The SSL based scheme strikes me as completely insane. PKI is a ton of work to maintain and this idea doesn't even address the crux of the issue, which is distributing full, proprietary OpenType / TrueType fonts.