"Tap the spacebar with your phone." - Bump unveils new photo uploader
photos.bu.mp
photos.bu.mp
https://github.com/bumptech/bump-api-ios
https://github.com/bumptech/bump-api-android
Email me if you have any questions: tg@bu.mp
IMO this is pretty shitty - I put this information into the app to send to other people, not so Bump can email me. And now I feel iffy putting other data into the app - Bump is not strictly the data exchange platform I thought it was.
This is a violation of user trust - if you want to store/act on any information users put into the app you need to let them know first.
This really, really rubbed me the wrong way - this is the first time any app of mine has ever intercepted a form field, sent it to the mothership without my consent, and used the data in a way that was never stated nor implied. App deleted.
[edit] Oh hey look, the email addressed me by the name I put into the vCard. I guess now you have my phone number too.
Clearly that's incorrect, because the complainer didn't want you to have his personal information.
Also the statement "We may use your Personal Information as we believe to be necessary or appropriate in any manner permitted under applicable law, including laws outside your country of residence" clearly gives you the right to sell his personal information to anyone.
Otherwise what's the point of having the address?
Seems like bump works better without enabling location, maybe because I prefer it to fail rather than to spy on me. Talk about not failing gracefully.
a) The user clicks somewhere (or vocal command?) to enter a listening state.
b) Then he shakes his phone.
Anyway, very cool and I could actually see a use for this, sending photos of whiteboards to colleagues that don't run Mac/have an iPhone. Would have to compete with email/dropbox for ease of use, but it does seem very simple on the receiving end, just surfing to a web page.
I get the mobile-to-mobile bump application, but can someone illuminate me on this one.
I say this as someone who did follow the link from HN, and I still can't figure it out.
Have I been hiding under a tinfoil hat for so long that I am completely out of touch with the world? Do most HN readers have these on by default?
[1] http://dl.dropbox.com/u/9061771/Screenshots/yebr_5sj_2ik.png
I tend to pick and choose on an app-by-app basis.
Two lessons from that:
1) Gather user feedback all the time, at any stage. Meet customers, send out surveys, interview users, whatever it takes to get the data.
2) Simplify! Your product needs to be as frictionless as possible (I think I repeated this like 7 times when I tried the demo). It's two steps to use the new Bump photo app -- that's easy for a user to understand.
NB: This is not trollfood and I am not a hater. I don't use an iphone so I may be missing something obvious.
It lets you authenticate without having to enter a username/password (less typing!) or having credential information already saved on that computer (which is a typical case if using someone else's computer.)
Similarly, if you're at a new computer and you want your phone to authenticate that computer, the computer just needs to display a QR code that your phone scans. The phone then authenticates to the service, sends the token in the QR code, and the computer you're at is trusted. Even easier than bumping.
I don't see how is this better than, for example, storing your photos into some dropbox-like service, but it is certainly a neat idea.
1) I don't get it, so I'm unlikely to think it's brilliant without trying. (So now I need a laptop to upload photos from my mobile?...)
2) I wouldn't download this to try Bump without some better explanation, especially given implicit data protection reputation of just about every big consumer-facing company these days (especially one that trades in contact details.)
3) The title is full of gratuitous editorialization, which is against HN guidelines.
Gimmick?
Generally very cool experience but I wonder how well the matching algorithm will scale though. You can't be getting all that many bits of uniqueness out of a single key press and a vague bit of browser location data right?
NFC to the rescue?
Anyway, can the devs make this more shareable? I wanted to share on Facebook but the FB-markup link looks very nondescript (bad title, no description text, crappy icon). So, I'm not going to share it. Some Twitter / FB links on the webpage would be great.
Hinckley, 2003: http://depts.washington.edu/dmgftp/publications/uist04/uist_...
Mayrhofer, 2007: http://comp.eprints.lancs.ac.uk/2230/1/TMC-2008-07-0279-3.pd...
Edit: I'm wondering how it works in a technical sense.
I don't know whether it's a good idea or not, but it's certainly a unique concept.
There's no real chance of this being man-in-the-middled since you have to confirm on both devices. And they're being intelligent about it - I just tried it with two laptops at once, and you get "someone's device" instead of the name of your iThing, and your iThing says "please try again" like this: http://cl.ly/1O33430M0i2c0i2T0z2U
Once you've approved, they have a browser + app pair of cookies for future pairings (not really exploitable, as it runs over https), which strengthens the single-pair guarantee to the point where it's about as good as it gets in any security model.
I'll need more convincing.
Once you've approved, they have a browser + app pair of cookies
Exactly what's keeping the cookie on the browser and the phone from being copied?
You must be leaving out some details. This doesn't strike me as "good as it gets."
SSL. Either you trust it or you don't. Similarly, either you trust the CAs to work (preventing a real MITM on https traffic) or you don't. Which makes this as secure as your banking site, except for the initial pairing, which I dare say they do more safely than any bank I've seen.
Keep in mind, all of the above exists already. Its just the elegant method of not having to put a PIN on both the phone + browser doesnt. Cool logon method.
An insecure login method does not a cool one make.
Wasting time on dumb features like that when the mobile app UI and constant nagging is like dragging your nails over sandpaper.
The idea is good, the best way so far to say "Bluetooth sucks".
Apparently they licensed their technology to Paypal to build their money-exchanging app. Maybe that's the plan.
It's been good to seeing Bump innovate again over the past few months.
And, of course, we're hiring. Come help us do this crazy stuff. Email me at jamie@bu.mp
I'm thinking they're using both your phone and computer's location + timing of accelerometer activation and spacebar hit to identify the phone and computer being bumped together.
Very neat.
Space bar triggers POST (content:{"category":"Bump","action":"NoMatch","time":1334124838.48,"client_id":"a7g47710-e991-721f-8bb6-ea4013a22fb6","session_id":"1509c654180344aea5660a0349b0caaf"}).
(1) Do this
(2) Do that
And then this happens!
However, the ultra simple two step instruction set on this page is neither preceded nor followed by a statement of what outcome is meant to occur. I mean, I figured it out, but it should be dead clear without thinking.
Huh, that doesn't seem to be a welcome comment. I'm not sure why. Bump doesn't strike me as an app that ought to require large media files. Does it contain any? If so, why? Is the binary itself that big? If so, why? Large dependencies? Either way, the size stopped me from checking it out: it takes up space on my device, it takes work to move it to the SD card and if it updates regularly that means more relatively large downloads.
But in my experience, 2.74mb is not a large iOS app.
> Uh oh!
> Sorry, there was an error connecting to the Bump service. Please try again later.
Why is there a step 2?
Q. What happened to the music bumping feature?
Listening to you and reviewing our usage data, it became clear that sharing music links wasn’t a great experience for you, our users. We have removed it for now to make the app simpler and easier to use.
Q. Why can’t I bump apps anymore?
Similar to music bumping, you made it clear that this was not a great feature and therefore, we have removed it to make the app simpler and easier to use.
Marketing tip: don't lie to your users in order to smoothen out the folds and creases, because that always rubs people the wrong way and always makes a company and its product look suspicious. Just say it like it is, "Sorry, guys. Copyright and anti piracy laws forced us to remove these features."
Not only are they playing fast and loose with insecure passing of private data, they also tell their users lies? Maybe deleting their app was the right choice for me.
HORRIBLE APP:
Nasty and painfully slow custom UI, I sent a photo then it asked me to rate it 5 stars on the app store. Then I browsed to send another photo and it asked me again to rate it after dismissing that it asked me a 3rd time with a fancy graphical popup.
NO THANKS BUMP, deleted. Someone please feel free to implement this idea succinctly.
Uploading something to a server just to share it with someone standing near you is ridiculous.
Terribly inefficient.
Sure, I can set up MY home computer to automatically pull pics from my phone, but I want to put it on Bob from work's computer... or the boss' iPad.
I would turn to email or dropbox before, but at first glance, this is a pretty damn elegant solution.
or:
1. open bump 2. go to the website on bob-from-work's computer 3. tap the photos you want to share 4. smack the spacebar with your phone.
Not really. For one thing, it greatly simplifies security concerns for the user without compromising anything.
It's the difference in immune system exposure between a pill and a hypodermic needle.
What you say is generally true for file transfer mediated by server. I am unconvinced it's specifically true for Bump. What I said still stands: security is inversely proportional to convenience. Often security is purchased up-front, paid for by inconvenience. With Bump, you "pay" via an app which uses a coincidence in time and space to "authenticate" you. Such a transaction usually works out, and is probably no riskier than giving clerk you don't know your credit card. (Another place where one gets convenience in exchange for privacy and security.)
In the case of transactions with serious downsides, should they go wrong, then users should be aware where there are compromises in security. Denying the truth of this is to spread ignorance.
I do not think that Bump is attempting to be secure in terms of keeping your images from being intercepted or that it is right to even describe what it does as "authentication". It would be more accurately described as "client selection". There is a niche of insecure file transfers to be filled though. For example, I sometimes send images to people via imgur, which is completely insecure, but sometimes I'm sending images and I don't care if other people can see them.
That is a very different kind of security issue than one that allows an attacker to control a device, which is the sort that I meant when I said that using an intermediate server doesn't open up security holes.
It is ridiculous from the technical point of view. It is ingenious for the users. I am sure that the question 'what else do we consider splurging' is the one that could uncover a lot of innovative uses of technology.