Almost all of the debug library was made unavailable to mods as well, for similar security reasons.
Almost all of the debug library was made unavailable to mods as well, for similar security reasons.
A preprocessor could spit out Lua code with the same effect and less complexity. Really interesting why and how these decision were made.
Factorio 1.1.101 (which the blog post says included the fix) does not list any changes regarding the disabling of bytecode or restricting the debug library. This would have been notable news, even without admitting the security risk. Factorio 1.1.107 does mention disabling the debug library, but it doesn’t seem this article had anything to do with that.
I believe the change was not mentioned in the changelog as an attempt at 'security through obscurity', trying to avoid people getting any ideas before the update is wide-spread. Not sure that helps any, but still.
I suspect the overwhelming majority of Factorio players are using Steam, which auto updates.
I would say that servers only tend to update when large features are released. So announcing a security vulnerability would likely push some servers to update.
I know I've held back my copy of Factorio due to some concern over changes in newer versions, preferring to letting the dust settle before upgrading to the latest stable version.