What tools (if any) are working in Glyphs 4 to protect webfonts from being installed and/or reversed engineered? Noticed that ”Webfont Only” does nothing to the font.
The “Webfont Only” custom parameter modifies some internals of the name table that makes the font less suitable outside of web fonts, but it is not a strong protection. I don’t think there is a good way to offer a one-click solution to protect web fonts (or even a many-click solution).
I’ve seen a few webfonts which (when you try to open them) either crashes the application or just doesn’t being recognised by a font editor. This was Woff2:s. I tried using Claude to do something similar, but doesn’t work. Well, not super important, this was for Beta-font only that I did not want to use on a website until released.
Did it worked for you with Glyphs3? I know there is no bulletproof solution, but I recently did some testing on those custom parameters and they did the job with G3.
Yes it worked in G3!
We had to disable some of the “protections” as the validation of web fonts became stricter and they would break the fonts on the web, too.
there is probably no way to protect your webfont from being reversed engineered or being downloaded …
I have tried a few methods in the past, nothing worked. Although if don’t mind the hassle, you can have a look at J-LTF.com. I think what they did is to export per style into 3 font files. So far that’s the only method I feel might work because it takes more time and effort the group the files in to one font file again. (It’s impossible to forbid people to download web fonts, as long as it’s loaded, so the possible method is to make second step harder — usually pirate sites convert web font to otf/ttf, I bet they have some kind of scripts to do it automatically, but imagine if you export “Regular” into Regular-A, Regular-B, Regular-C…each subsets some glyphs…