Awesome post. I worked with cloud.typography for a client once too, and was surprised to discover that they shipped two base64-encoded data strings for each font, each one containing only one half of the font's glyphs – that is to say, their CSS had two @font-face rules for each font: one that had the data for e.g. A-M, and the other that had data for N-Z. The `font-family` rules of the body text specified both FontA and FontB, leaving the browser to piece the font together. Of course, this made extra bloat in the base64 string, because it's essentially two encoded font files instead of one.
I assumed this was for anti-DRM / licensing purposes, so that if someone tried to download the font shipped to the client, they wouldn't get the whole alphabet (even though it's fairly trivial to stitch fonts together – you can use FontForge to copy/paste glyphs from one font to another). Do you know if they still ship fonts with a split alphabet?