"EnTerr" wrote:
In this case he ummm, "embellished the truth" by conjecturing that showing info screen on a channel somehow places it in the official Channel Store context.
Less tech savvy users, arguably the larger percentage of the Roku population, could very easily be fooled by that, since there's no way to get to a channel details screen on the Roku aside from going through the channel store. I didn't even realize it was possible to point the channel store to a private channel like that, so it's even possible I'd fall for it.
Are there ways to prevent that while keeping the functionality? Of course there are, but that's not what was being discussed. I was just offering a suggestion, as you did as well, as to why Roku may have decided it was a security risk.
"roquoonewbie" wrote:
Only a malicious ECP could/would covertly launch the channel store screen for a private channel the user had not expressed any interest in installing.
That's my whole point. It sounds like maybe you think I'm accusing
you of wanting to exploit it that way, which is about as far from my intent as you can get. The fact that a malicious ECP app (not yours!)
could do it is exactly why it could be considered a security risk.
"roquoonewbie" wrote:
And again, if it could do that, it could equally launch the web browser to the add channel page as well...which looks just as "official" as the channel store screen.
There's a major difference there in that you have to be logged into the Roku website to add a channel via the web browser, and automating the install approval process in the web browser is much more involved than just sending a few remote commands via ECP.
Look, I get that you and EnTerr have a vested interested in having this functionality, and I'd likely be equally as upset if I were using it and it suddenly disappeared. Labeling me a Roku fan-boy/Roku apologist, however, doesn't diminish the validity of any of the points I've made. With that, I'm done with the conversation, and hopefully Roku will come along and clarify why they decided it required a "security fix" and possibly even be open to addressing it a little less aggressively than just killing it altogether as they have done.
My Channels: http://roku.permanence.com - Twitter: @TheEndlessDev
Instant Watch Browser (NetflixIWB), Aquarium Screensaver (AQUARIUM), Clever Clocks Screensaver (CLEVERCLOCKS), iTunes Podcasts (ITPC), My Channels (MYCHANNELS)