Live data from Hacker News

"Tap the spacebar with your phone." - Bump unveils new photo uploader

photos.bu.mp

121–130 of 151 posts

Re: "Tap the spacebar with your phone." - Bump unveils new photo uploader

#121
post #118

Earlier quoted context omitted.

Outlook is an application, not a web connected service, though. If I enter my email address when signing up for, say, Office Live, I'd expect to see a Microsoft email in my inbox every now and then.

Would you expect Google to send emails to people whose addresses have been entered into Gmail?

No, but that's not what happened here. You filled out your personal card which will be shared out with everyone you "bump" with. I haven't used the app, but I'd assume this fills some kind of registration function.

Re: "Tap the spacebar with your phone." - Bump unveils new photo uploader

#122
post #118

Earlier quoted context omitted.

Outlook is an application, not a web connected service, though. If I enter my email address when signing up for, say, Office Live, I'd expect to see a Microsoft email in my inbox every now and then.

Would you expect Google to send emails to people whose addresses have been entered into Gmail?

Bump emailed the guy that used their service. Your stretching the analogy a bit much.

Re: "Tap the spacebar with your phone." - Bump unveils new photo uploader

#123

Earlier quoted context omitted.

No, there is always a compromise in security and privacy as part of the price of convenience.

There is no additional compromise. If you go opening up sockets directly between devices, you open yourself to new exploits if you don't implement that communication correctly. If you use a server in the middle, you can just use HTTP and leverage built-in, strongly vetted web browser code that was already there. And if that code has security holes, they were already available to attackers before your app came along.…

There is no additional compromise.

What you say is generally true for file transfer mediated by server. I am unconvinced it's specifically true for Bump. What I said still stands: security is inversely proportional to convenience. Often security is purchased up-front, paid for by inconvenience. With Bump, you "pay" via an app which uses a coincidence in time and space to "authenticate" you. Such a transaction usually works out, and is probably no riskier than giving clerk you don't know your credit card. (Another place where one gets convenience in exchange for privacy and security.)

In the case of transactions with serious downsides, should they go wrong, then users should be aware where there are compromises in security. Denying the truth of this is to spread ignorance.

Re: "Tap the spacebar with your phone." - Bump unveils new photo uploader

#124

Earlier quoted context omitted.

There is no additional compromise. If you go opening up sockets directly between devices, you open yourself to new exploits if you don't implement that communication correctly. If you use a server in the middle, you can just use HTTP and leverage built-in, strongly vetted web browser code that was already there. And if that code has security holes, they were already available to attackers before your app came along.…

There is no additional compromise. What you say is generally true for file transfer mediated by server. I am unconvinced it's specifically true for Bump. What I said still stands: security is inversely proportional to convenience. Often security is purchased up-front, paid for by inconvenience. With Bump, you "pay" via an app which uses a coincidence in time and space to "authenticate" you. Such a transaction usually…

Well, I have no idea if Bump uses HTTP and such to do this via vetted methods or if it is really secure in terms of opening your device up to attack vectors. I was making the general point that transferring files between proximal devices by uploading to an intermediate server isn't inherently pointless.

I do not think that Bump is attempting to be secure in terms of keeping your images from being intercepted or that it is right to even describe what it does as "authentication". It would be more accurately described as "client selection". There is a niche of insecure file transfers to be filled though. For example, I sometimes send images to people via imgur, which is completely insecure, but sometimes I'm sending images and I don't care if other people can see them.

That is a very different kind of security issue than one that allows an attacker to control a device, which is the sort that I meant when I said that using an intermediate server doesn't open up security holes.

Re: "Tap the spacebar with your phone." - Bump unveils new photo uploader

#126

I've been getting this for a while: > Uh oh! > Sorry, there was an error connecting to the Bump service. Please try again later.

3 hours after your attempts I got the same error. Looks like they aren't ready for this rush.

Re: "Tap the spacebar with your phone." - Bump unveils new photo uploader

#128
What does this do? I know because I saw the headline here on HN, but if I went to the site without context, I'd have very little idea, and I'd have to do some detective work or deductive reasoning to find out. It's mostly obvious, but I think it'd really help to have a super-brief explanation of the function - like maybe instead of "Tap the spacebar with your phone," it could say "Tap the spacebar with your phone to upload photos."

Re: "Tap the spacebar with your phone." - Bump unveils new photo uploader

#129
post #73
post #55

Earlier quoted context omitted.

Slightly disturbing that you don't get any confirmation to share on the mobile side, it just sends your data off to whoever it matched with immediately :-/ Generally very cool experience but I wonder how well the matching algorithm will scale though. You can't be getting all that many bits of uniqueness out of a single key press and a vague bit of browser location data right?

I think it can scale by bumping more times (1-3 is ok for people and it will triple your space). But even with this, the non-geo-located (or poorly located) browser will become unusable by oh-so-many conflicts when you have certain amount of users using it.

If you think about it, it's a paradox. For this to be vaguely useful, lot of people must use it. When a lot of people start using it, the system breaks.

NFC to the rescue?

Post reply on HN