top | item 40831574

(no title)

Therenas | 1 year ago

I work on the game. The debug library was disabled for other security holes that were brought to our attention, so it wouldn‘t be related to this, but I thought it was interesting to mention.

I believe the change was not mentioned in the changelog as an attempt at 'security through obscurity', trying to avoid people getting any ideas before the update is wide-spread. Not sure that helps any, but still.

discuss

order

deely3|1 year ago

Sorry, but thats just a perfect example why 'security through obscurity' is wrong. I have zero idea about security risks, but if fix does not mentioned anywhere, then for people that use previous version there no rush to upgrade.

TillE|1 year ago

> no rush to upgrade

I suspect the overwhelming majority of Factorio players are using Steam, which auto updates.

Therenas|1 year ago

I don‘t disagree.