Does anyone else think there might be a significant security value in not allowing a web browser access to a font associated with messages from the operating system?
Besides, malware authors generally cannot be expected to follow copyright law. They can just steal the system font OTF and convert it to a web font, or render text as an image (which may not even be illegal), or any number of similar things.
It seems like this boils down to DRM on the font -- only making it accessible to Apple-signed applications (not even to third-party apps, since I can write a third-party app that pops up a custom error message and then take a screenshot of my app). This is untenable for the usual reasons that DRM is untenable.
Cf. http://www.guanotronic.com/~serge/papers/fc15-fonts.pdf & http://pet-portal.eu/files/articles/2011/fingerprinting/cros...