Tell HN: GitHub refuses to remove cracked copies of my software after a month

502 points by IvanK_net 1 day ago

I am a developer of https://www.photopea.com, a popular photo editor that runs in a web browser.

Many people are asking AI models to take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download.

There exist tens of such repositories on Github. I want my website to be the only source of a stable version of my program Photopea. I even received emails from people complaining about something in Photopea, and it took several emails to figure out that they are not using Photopea.com (so it ruins my reputation a little).

I reported it to Github on the 4th of September 2026: https://www.photopea.com/g/XKoqqIGv

Today, a month later, I received this response:

Thank you for submitting a DMCA takedown notice. We've reviewed the information you've provided, and based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201.

What do you think I could do? Do you think I should look for a lawyer to deal with it outside the digital world? I really doubt that a real person ever looked at my report, and they probably send this response automatically to 99% of people.

DannyBee 9 hours ago

IP lawyer here - I can't give you actual legal advice because you aren't my client, but generally, you have two options here, neither of which will be surprising, or very satisfying:

1. Pay a lawyer or firm that specializes in this sort of thing to play whack a mole for you

2. Accept it as normal losses and ignore it.

Contrary to others claims here, it is not a 500/hour thing to do #1 when dealing with firms that specialize in this. it probably would be if you just hire a random one-off IP lawyer to try and deal with this particular instance.

Trying to deal with it yourself will be increasingly frustrating and time wasting for you. You will also never be able to prevent someone sufficiently motivated from doing stuff like this to your software.

Unless you want to spend your time dealing with those folks instead of building the software, you should hand this part off - it's not a good use of your time, value wise.

Put another way: most companies farm out processing of this sort of request to high volume low cost processing teams. Or AI. Or both. For you this is an important one off. For the person processing it it's one of a hundred tickets they are handling today. You are not going to get very personalized attention and consistency.

I don't claim this is how it should be, etc. I simply claim this is how it realistically is. It would practically require legislative change to have a different thing happen here and while interesting to discuss, that seems outside the scope of your questions, which seemed more practically oriented

  • monster_truck 7 hours ago

    I've spent 0 seconds googling this so excuse the dumbfuck question but: is there any precedent or convention for writing off the stolen goods as losses? I'm pretty sure physical goods from businesses qualify but what about this??

    • ktm5j 7 hours ago

      Digital losses to piracy sounds like something that would be impossible to quantify.. even if they can prove that people are downloading these pirated copies, that's not proof that the downloader was ever going to pay for the software in the first place.

    • DannyBee 7 hours ago

      Physical/digital has the same answer, just different effect.

      As a general rule, you can write off what it costs for you to make something, but not what you lose from not being able to sell it.

      Which means for physical goods, you write off the cost to make them, and for digital goods, you can similarly usually deduct development cost to make the software.

      In neither case can you write off the amount you would have made had it not been stolen/sale had not been lost.

      The practical effect is that because physical goods have a per-unit to-make cost, and most digital goods don't, physical goods get written off per-unit-lost and digital goods do not.

      At least, this is the most general answer I can give you for that level of general question.

      • plumbees 6 hours ago

        Could you just make a CICD process that for each minting of a software license it cost a person's time to review and accept and then the wages for that individual become the write off. I.E. Convolute the software delivery process so that like a physical good, it has a per-unit to license cost to recoup. Or would that be argued as it could have just been automated and it's not really a real loss leader just bad policy?

        • thenewnewguy 6 hours ago

          You don't lose this time for pirated copies of your software, as I assume you aren't taking this person's time to create a license for pirates.

          To write something off you have to actually lose the money - writing off is a process to decrease your taxable income by your expenses, unless you're inventing fake expenses (read: performing tax fraud) it doesn't generate a greater amount of money than the expenses.

  • voakbasda 7 hours ago

    What I am hearing is “there will be no justice here for you.”

    The bad guys are winning, because the good guys have no legal recourse. The only practical solution is vigilante justice, but that makes you a bad guy.

    In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice?

    • cassonmars 6 hours ago

      The question is not how then is one supposed to trust the law, because you already know the answer. The question is what one does about it.

    • keybored 6 hours ago

      This is HN so nothing else to expect than Big Tech people giving us the scoop with the tagline "let's be realistic here".

    • throwaway27448 6 hours ago

      I imagine most people don't expect actual justice in life.

    • DannyBee 5 hours ago

      Let's separate criminal and civil here, because this is all civil law.

      Civil law systems largely aren't about "good" or "bad". Justice there isn't "good guys win" and "bad guys fail". It never has been.

      It's about trying to reasonably resolve disputes. That's all. Civil legal systems were created not to enforce morality or social order, but instead to formally resolve disputes. The system is pretty good at doing that. It will never resolve all disputes, let alone resolve all disputes in an "optimal" way (for any possible definition of optimal you come up with). It only tries to do a reasonable job of it.

      If your expectation is that the law will stop "bad" actors from acting "badly", i think your expectations are out of whack. Yes it gets tried, but it is a fairly miniscule portion of the system overall, and generally not a very successful part of it. It's also remarkably recent in the history of legal systems. It is a quasi-political thing that the legal system simply isn't good at dealing with, and really is not a good match for it. I think results bear that out so far

      You can take that for whatever you want - I can only tell you why the system is there, historically and currently. That doesn't mean you have to like that idea, and you are welcome to rail against it.

    • 45sdasf45 5 hours ago

      What if writing proprietary and/or non-free software was the real evil? LLMs have made everything open source. All software is free now.

      The Justice is the liberation of code from those that wish to seek rent from it.

    • mschuster91 5 hours ago

      > In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice?

      Guess why trust in democracy itself is eroding everywhere and why even executing a health insurance CEO on broad daylight is not just widely approved but widely beloved.

      The rich can get away with anything (Trump's claim of "I could shoot someone on 5th ave and get away" is pretty realistic, to say nothing about the Epstein crap), but if you are poor or, even worse, an immigrant - pray to God to help you because not just will no one else help you, but in the worst case you might end up getting fucked over for seeking help.

    • bsoqk 3 hours ago

      This is what HN has devolved into: someone taking adware and removing the ads is a "bad guy".

      • cpach 2 hours ago

        Well, shouldn’t that be up to the original developer? He made a product and let people use it for free. But no-one is forced to use it. And there are other image editors without any ads. Some are proprietary, and some are FOSS, e.g. GIMP.

  • tim333 6 hours ago

    Not a lawyer but I have friends get some results getting an LLM to send threatening lawyer type letters.

  • keeda 4 hours ago

    Since you're here and on topic, a question that has been at the back of my mind because I feel that soon most software creators will be in this boat, with AI rapidly becoming able to clone software from observing behavior alone:

    Are patents the only real IP protection left for software?

    And would a patent (assuming this application had something patent-worthy to claim) help at all here? As in, in addition to sending a C&D maybe also including language about patent infringement would be more effective?

    I know that patents are unpopular for many here (including you, IIRC!) but I think this question is extremely important, especially to anyone who wants to make a living purely off the software alone.

    Remember: if no other moats or business models or funding models lend themselves naturally to the software in question, anything bolted on is pretty much already on the slippery slope to enshittification. A mechanism that encouraged people to compensate fairly for the value provided by software would be better for the Internet than what we've got going on today.

    • nradov 4 hours ago

      The only effective protection for software IP is hiding the logic on servers you control (SaaS). Anything released to execute on client hardware can be decompiled and cloned. This has always been the case but LLMs have made the issue more obvious.

      • modzu 2 hours ago

        there is no more software IP. ai does not need source: it can infer or deduce the logic or algos. and in the case of private software dont think it hasn't been sucked up too

  • kittikitti 2 hours ago

    You are the scourge of Earth and I hope you stop recommending how to "whack" developers. People like you are basically the mafia for Big Tech. I have been targeted by your industry for doing nothing wrong multiple times.

    • cpach 2 hours ago

      Please don’t attack other HN members. It’s not nice and it’s against the guidelines.

      • kittikitti 2 hours ago

        The poster recommended to "whack" developers and I merely pushed back on that. Please have better reading comprehension before playing police.

        • cpach 1 hour ago

          I’m no cop. I just want HN to keep being a civil place. I hope you agree :)

thought-gap 17 hours ago

First off, let me get this out of the way - I am not a lawyer. If you want a legal advice talk to a lawyer.

Second, I am sorry this is happening to you.

Third, based on GitHub's reply, specifically

> we're unable to confirm a violation of 17 U.S. Code § 1201

they took your submission as 17 U.S. Code § 1201 takedown notice. Maybe you specifically stated this. Maybe it was implied. This is likely not what you want and GitHub's response is likely correct. The reason for this is that § 1201 prohibits circumventing a technological measure. The JS you host on your public site, even if obfuscated, very likely does not qualify for this protection. Another detail - the reason it took long (a month later according to your post) is that after the youtube-dl fiasco, they committed to manual review, legal and technical, of every 1201 takedown notice [0].

Fourth, if you believe these copies are sufficiently reproducing your copyrighted work, what you likely want to do is file a standard copyright infringement 17 U.S Code § 512(c) takedown notice. This still goes through the same DMCA report flow but it should result in a less stringent review process and a faster response.

Fifth and finally, consider asking your favorite LLM to get more context around these laws. Good luck!

[0] https://github.blog/news-insights/policy-news-and-insights/s...

  • apefulsin 8 hours ago

    Circumventing a technological measure has been interpreted extremely broadly. Deobfuscation could be covered.

  • eli 7 hours ago

    This is bad advice. Obfuscated JS qualifies.

    1201(a)(3): "As used in this subsection-- to 'circumvent a technological measure' means to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure, without the authority of the copyright owner"

    • darkwater 6 hours ago

      Obfuscated JS can be re-hosted as is, and you can probably remove the ads with newly added JS code.

      • eli 6 hours ago

        Or just visit the real site and use an ad blocker? Re-hosting it would obviously be copyright infringement.

        • Maxatar 3 hours ago

          Ad-blocking breaks the original site. A lot of functionality stops working properly.

          • eli 1 hour ago

            Sure, seems only fair that if you can try to block ads, the app can try to detect ad blockers.

    • keeda 4 hours ago

      The problem is that AI can probably rewrite this JS de novo simply by observing its behavior and without de-obfuscating it.

      • cute_boi 4 hours ago

        Or just ask first AI to create specs and another AI to do clean room implementation?

        • eli 1 hour ago

          I think you would just end up with yet another slopcoded photoshop clone

  • tothrowaway 7 hours ago

    Indeed, a 512(c) takedown notice is the way to do it. GitHub is extremely unlikely to ignore it. I run user generated content websites and would never ignore a notice. You definitely don't need to hire a lawyer to write it either. Just follow the notification guidelines in 17 U.S Code § 512(c)(3).

gwbas1c 8 hours ago

> take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download

Remember that there is still quite a bit of friction to doing that, and that many people have better things to do than jump through those hoops.

In addition to the "hire a lawyer" comments in this thread, I suggest building in some heuristics that detect when Photopea is running outside of your domain. They don't need to be "foolproof," but add additional friction to pirating Photopea so that less people will jump through the hoops.

Some historical examples:

- Commercial software in the 1980s and 1990s would burn a hole on the disk, and the software would look for the error when reading that sector.

- Donkey Kong Country would detect that it was pirated by reading the amount of RAM available. (Because SNES backup systems had slightly different runtime properties than the real cartridge.)

More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.

---

Finally, you could consider a business model that relies on server-side functionality for revenue or stickiness, that's hard to replicate merely by pirating the software. (IE, some kind of server-side storage and sharing system.)

  • svantana 8 hours ago

    > Remember that there is still quite a bit of friction to doing that

    If they're using the github.io repo, the web app can be just as accessible as any other site

  • abcd_f 7 hours ago

    > More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.

    This is a very frequently repeated point, which is invalid.

    Crashing pirated versions do not affect the reputation of the original. It’s an urban legend.

    People using pirated versions are perfectly aware of the fact that they are using butchered versions of the original. So when it crashes, chances are it's because of a botched DRM bypass. It's an obvious connection, has always been.

  • ravenstine 6 hours ago

    Techniques like what you describe made a little more sense when the means to even figure them out were less feasible for the average person, especially before the web had much information on reverse engineering, when powerful debugging tools weren't as accessible or free.

    Today, there is little point in trying to slow down software pirates. At best, adding an arbitrary piracy detection only adds anywhere between mere minutes and a few days to the effort to crack software. This is true absent AI assistance or even a meaningful understanding of ASM outside of logical JMP instructions. The author will likely waste more of their time implementing anti-piracy techniques than a software pirate would figuring out which function call results in the program exiting abruptly. I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities. This is in spite of various licensing and contextual checks throughout.

    It would slow down a pirate more to have a program modify or decompress itself in memory, but that class of techniques is still more trouble than it's worth. Experienced pirates already know how to deal with those traps. The timeout thing you mentioned is clever, but the type of person who knows enough to disassemble software would think to themselves "wtf does it crash after 5 minutes?", immediately investigate, and identify the source of the crash.

    Having a license check is the only thing authors of software should bother with. It provides most people a framework to consider whether they should pay for a product. Most people won't download potential malware from a sketchy website if you offer your product at a fair price. Those who either know how to crack apps or refuse to pay will keep doing what they're doing.

    tl;dr Don't fool yourselves into thinking you'll outsmart a kid with Ghidra installed by throwing a glorified if-statement in their path.

    EDIT: I'm speaking in the general sense. The same principles apply to an app that runs almost all of its logic in the browser.

    • eps 5 hours ago

      > I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities

      There are some, with code consistency cross-checks and such. Cracking them with static code patching can get very time-consuming. Patching them dynamically works, but some have checks for that too. It's not common though for sure.

      • ravenstine 3 hours ago

        Yeah, I'm sure they're out there, but it's very rare in my experience. I'm a micro-brain when it comes to cracking software, and I've almost never encountered this, whether it's small fry software or something from Microsoft or Autodesk. There was some software with debugger detection I came across once (can't remember which it was), but that's the kind of thing where lots of existing workarounds often exist by other crack-ers.

        • Timon3 2 hours ago

          I'd recommend taking a look at DRM for games. It's been a while since I read anything, but AFAIK Denuvo is still effective enough to protect newly released games for weeks.

      • SleepyMyroslav 2 hours ago

        I've spent some years in gamedev and doing PC versions was a big part of it. I have seen countless attempts at 'code consistency cross-checks' and they all have been defeated. The only thing that came close was Denuvo. You may want to read up on it before dismissing it. It's sad that folks here will downvote and hate anything about it. What it changed is that publishers got their money from people playing on PC and some of it was spent on developers to actually improve future games =)

summarity 13 hours ago

Is there a ticket code or other contact you've been in touch with?

As for DMCA filings, we publish all of them here: https://github.com/github/dmca

I see two from Photopea, one from 2022 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) and one from 2024 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) - could you point to the recent filing?

I work at GH, but am not involved in DMCA filings, and can in no way answer or judge this case, but potentially follow up internally.

  • IvanK_net 12 hours ago

    Thanks! One is Ticket 4822535, another is Ticket 4726557.

    Github did take down this https://github.com/spooknik/Photopea-Appimage and other repos in the past, but now, I feel like I talk to a robot. I am happy to hear that they have real employee! :D

IvanK_net 15 hours ago

Hey guys, thank you all very much for your comments! I just woke up, I did not really believe my post would get this much attention, so thanks!

Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.

I think I will try solving it with a lawyer. But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.

  • brnt 15 hours ago

    > But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.

    I think anybody in any line of work or life would like that. It's however unlikely to never run into an issue where a lawyer is really needed, so don't hesitate when you realize you need one.

  • Qwuke 11 hours ago

    I've used Photopea for small editing before, and even though it's not my daily driver, it's a really cool project.

  • graemep 9 hours ago

    A lawyer will probably get you damages for the infringement and is less hassle than trying the whole process yourself.

    • gpugreg 8 hours ago

      I could find are a bunch of Photopea repositories on GitHub, but the authors are all either from China or Russia, so getting damages for infringement will be difficult to enforce. Hiring a lawyer sounds like a waste of money to me.

      • graemep 7 hours ago

        You might be able to get damages from github, especially as they have ignored a notification that there was infringing material. A lawyer would know.

        The US allows damages per infringement without need to prove an actual loss, and per infringement.

        • dannyw 6 hours ago

          We don’t know if OP filed the DMCA “optimally”.

          In my experience GH usually does 512(c) takedowns in days; so it taking a month is quite abnormal. OP’s posted response suggests he didn’t file a copyright takedown but rather an anti-circumvention claim; which is a bit special in DMCA law, and generally best avoided when you have merits to do a regular 512(c).

          We also don’t have details of the repo. The author has commented on another project that claims to be a LLM _re-implementation_ of Photopea, without directly using source. If that’s the case, it’s entirely understandable why GitHub won’t take it down.

          • zdragnar 6 hours ago

            Github supposedly manually verifies 1201 claims, which would explain the long wait on the response.

    • kevin42 6 hours ago

      Sadly though, you have to do the cost/benefit analysis of the legal process and your likelihood of recovering anything.

      I spent $18k in legal fees over a $22k claim in a construction dispute. I won the suit and was awarded legal fees. So I'm owed $40k plus interest. I've collected exactly $0. The last lawyer I spoke to said I need to cut my losses in legal fees at some point because from a practical standpoint, winning damages isn't the same as collecting them. Especially if the defendant isn't local and has few assets.

  • hermitcrab 8 hours ago

    >Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.

    It worked for me! And very quickly.

    https://news.ycombinator.com/item?id=49832406

    But it is a bit crap that this is the only way you can get Github to behave responsibly.

    Good luck.

JohnFen 23 hours ago

You should discuss this with an attorney that is experienced with IP law to see what your options really are. IP law is very complex and sometimes very surprising. You need expert legal advice, not advice from the HN crowd.

As an aside, I thought that "cracked" software meant software that has had the copy protection or other access control bypassed or removed, not the alteration of the software functionality itself. If your software was actually cracked then you may have some fairly heavy law in your favor. For better or worse, bypassing access controls (even weak or simple access controls) gets special legal attention.

  • y-curious 17 hours ago

    What is the cost for doing this, out of curiosity? If OP only earns a trickle of revenue from their site, it probably isn’t even worth the money (?)

    • Onavo 16 hours ago

      He earns 7 figs a month from it iirc, was featured many times on HN as a successful indie hacker.

      • janalsncm 16 hours ago

        If that’s true, he doesn’t need free legal advice from us.

        • msdz 16 hours ago

          True, but then again, the post is titled “Tell HN”, not “Ask HN”. Maybe it’s just a case of the poster trying to raise awareness.

          • pluc 11 hours ago

            ... they're just trying to get the attention of someone at GH that can do anything OR create bad press that they then have to deal with. But pressuring them on HN to act about their sub-par anything is.. arduous, given their.. tolerance.

      • jasode 12 hours ago

        >He earns 7 figs a month from it iirc,

        Less than 7 figures (~1 million) per year -- not per month -- based on previous comment from 2021: https://news.ycombinator.com/item?id=26769141

        A later 2023 interview updated it to ~$200k/month (~2.4 million/year) : https://web.archive.org/web/20240606073354/https://saastrapp...

        • fg137 10 hours ago

          Still enough to hire a lawyer and at least do a few consultation sessions. That's a necessary business expense.

          (I'd just quit my job if I had an income like this.)

        • schnebbau 10 hours ago

          That comment was over 5 years ago. That's a long time, and from estimates he has millions of users now. Definitely making big money.

    • janalsncm 16 hours ago

      A lot of lawyers will give a free consultation, and in my experience (not for IP) they will give decent expert advice for free. No harm calling them.

    • Shank 16 hours ago

      Most state bar associations have a free consultation line that will refer you to a reputable lawyer to start with and do basic consultation on where your issue should go and how much it will be. If I had to guess, getting advice is probably $100 and having a lawyer send a letter is $250-500.

      • Scaled 11 hours ago

        IP lawyers tend to be at the more expensive end, typical billing rate in US of $500/hr last I looked. But yes, being able to do a letter quickly is probable.

turtlebits 28 minutes ago

Piracy is rampant, platform providers aren't going to be able to keep up, especially in this AI age.

IME, the best route is to disincentivize it, make it harder to copy (obfuscation , etc) or just change your product/lower friction.

If people don't want ads, offer a low-cost ad free option. Having auto-play video ads is extremely distracting.

bartread 22 hours ago

Man, some of the comments this is getting are absolutely wild.

OP, I’m sorry this is happening to you. It must be incredibly frustrating to have people ripping off something you’ve worked on for many years and pass it off as their own work. I would be furious in your position.

I wish I could do something directly to help you but the best I can offer is to echo the best advice others have already given you: it’s time to get a lawyer. That is the one guaranteed route to get GitHub to sit up and take the action they should already have taken on your behalf.

hgs3 6 hours ago

The 3rd U.S. Circuit Court of Appeals recently ruled [1] that using AI to train on a competitor's copyrighted material to build a competing product is _not_ fair use. This is a recent ruling (September 30, 2026). GitHub policy has surely not caught up yet and who knows when it will.

> Do you think I should look for a lawyer to deal with it outside the digital world?

Absolutely. This is a copyright infringement case and there is now an appellate precedent to cite. Gather as much evidence as you can and speak with an IP attorney.

[1] https://www.reuters.com/legal/litigation/unsealed-opinion-sh...

  • hungryhobbit 6 hours ago

    ... and we all know our idiotic/corrupt Supreme Court can and likely will overrules that very sensible ruling with something crazy ...

    ... so virtually no one considers that ruling to be the final word on the topic (sadly).

  • alightsoul 5 hours ago

    How is this enforceable with llms if they train on generalist material, which is already the case?

    I don't think it's enforceable or even applicable here. "The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content "

    this comment is misleading.

  • keeda 4 hours ago

    You're right that this is a copyright infringement case, but I'm not sure if AI is relevant here, as it seems like a pretty straightforward rip-off.

    Also TFA is about a much narrower ruling than it first seems:

    >The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content — and the appeals court said in a footnote that concerns raised by the US Department of Justice in a copyright lawsuit against OpenAI "do not apply here."

jodrellblank 7 hours ago

You’ve made a million dollars a year for five years with it? Why are you stressing about lawyers and support tickets instead of being retired?

  • fishgoesblub 7 hours ago

    There can never be enough money for these people.

    • TheSkyHasEyes 7 hours ago

      C'mon. Poster has a valid concern here. We do not want places like github drag their feet for a month over such concerns...at least I don't.

    • MiloLeo 5 hours ago

      What exactly do you mean by 'these people'?

  • thraway3837 4 hours ago

    This is a really weird take. OP worked on this during all of their free time for over 10 years. And it finally took off into making a solid revenue for them. This is a rare success story for an indie developer. We should be supporting them. It would suck for anyone to get their life's work stolen and given away for free, which is what is happening here.

    -Another indie developer who hopes to have 1/100th the success that Photopea has had.

schnebbau 13 hours ago

I think we're going to see a lot more of this going forward.

I think we're also going to see the strategy to be to remove the processing and magic sauce from the client and move it to the server where it can't be decompiled and rebuilt with AI.

  • lesspassiveobse 12 hours ago

    You think AI can't recreate it based on the outputs?

    • ChrisRR 12 hours ago

      Maybe it can, but that's not what this post or comment is about

    • schnebbau 12 hours ago

      1:1? No, because AI won't know all the outputs, only the ones you show it.

      Also if it could recreate it that would be fine, because it would be doing so without having access to the source.

      • pixl97 10 hours ago

        >only the ones you show it

        This doesn't sound that hard to automate these days.

      • alpaca128 9 hours ago

        > because it would be doing so without having access to the source

        I find it unlikely that photopea was never scraped for AI training considering they are looking so hard for new material they started buying up and scanning old books.

    • 1718627440 12 hours ago

      When it can do that, the people can also describe the output, i.e. the fact that your original website even exists is irrelevant for what people are able to do.

  • TeMPOraL 12 hours ago

    This ship has already sailed, and most people in tech circles didn't even notice.

    SaaS killed Open Source with it, two decades ago.

  • anakaine 11 hours ago

    Apps like photopea exist because of client side processing. They shift cost to client compute and that makes them supportable by indie devs.

    I'd wager we will start to see more web apps like this have greater obfuscation and dependencies on operating on a particular domain. Sure AI can help to circumvent many things, but at a certain point they pay-off may not be worth the effort.

  • fg137 10 hours ago

    Since these clones already exist, it means that even if Photopea moves to server based (which it should have been in the first place), the code is around and will work forever.

    The magic sauce haven't been in the client for many applications for years. Google barely has any application that runs on desktop OS even though they could have released them.

    • jasode 9 hours ago

      >, it means that even if Photopea moves to server based (which it should have been in the first place),

      It's a 1-man operation so it may have not have been financially viable to architect the app as server-based.

      - server-based : must invest a lot more money in server farms and extra disk storage, or pay high AWS cloud fees. E.g. if a million users do a blur or denoise filter, all that cpu processing has to happen on the servers, and massive disk space to hold the intermediate files, and extra bandwidth costs to send the changed bytes back to the client.

      - client-based : just ship Javascript blobs to end users' web browsers because the blur/denoise/etc filters happen on the desktop.

      Also, this type of pixel-editing software still needs a ton of client-side Javascript to behave like a Photoshop clone because users want to see interactive changes as they dynamically slide the blur/noise/etc settings. Round-tripping that with extra server latency is not a fluid UI experience.

      We can't confidently replay the past and say that starting it as server-side app from the very beginning means he'd have the same $million in revenue today. Instead, the extra server costs and UI jankiness could have doomed the project.

      • fg137 9 hours ago

        I understand all of that.

        It's a business decision, and I'm not sure if they made the right decision. Most client-only web applications are open source because they know there is no business in selling it as a service. Photopea somehow is an exception, but its business model is getting questionable which is not a surprise at all.

        It's also possible to use a combination of cloud based and local computation. Figma is doing quite well in that regard, especially with the use of WebAssembly. No doubt that potentially means more work, and potentially forcing users to create account etc. But hey, that's a business decision as well. If you don't do anything but just keep everything in JavaScript, this was going to happen.

    • flomo 2 hours ago

      > server based (which it should have been in the first place)

      Server-based photoshop clone sounds more like VNC/RDP, for this sort of thing client processing is a better UX.

lewelove 9 hours ago

With all due respect: people should be able to do this. Copyright as a concept applied to code was always a god-awful idea, DMCA especially. And for JS served on the open web it's plainly comedic.

Someone can always make a new repo without redistributing your code, sourcing and hot-patching it directly from your domain. GitHub deleting this repo won't ever fix it, you're playing whack-a-mole and doing free PR for these repos here on HN.

We seem to forget that this website is called Hacker News.

  • fn-mote 9 hours ago

    I would like to think more deeply than this response.

    I do not want enshittified software that creates a bogus need for a server in order to extract licensing fees from me. I prefer to pay for locally run software, paying in ad views if I have to because that’s the micropayment system we have ended up with.

    So is there a path to an ethical, viable business model for the author?

    • gewetensleegte 9 hours ago

      > is there a path to an ethical, viable business model for the author?

      .. is something the author should have considered before deciding to publish AdWare.

    • RugnirViking 9 hours ago

      In an era of slop, quality is king. I honestly think the author should just ignore the cheap clones and continue selling quality software. The idea that the clones are perfect, bug free, or will continue to be maintained and hosted is a fantasy. There will always be people with low incomes in the third world trying very hard to get something for nothing/cheap, and they are the worst customers. No loyalty, highly intelligent, and will drop you immediately if a competing offer is 1% cheaper or offers what they need for free.

      Adverts are likely a poor business model here - if you want to sell to professionals and creatives, the visual look of the software matters. It should really be subscription or one time licence

    • ang_cire 9 hours ago

      Sure. One example of a path, that many people are already doing, is a system like Patreon.

      The old model of server-locked licensed software is going the way of the dodo pretty fast right now, though people may not realize it if they're not hunting for alternatives to the old guard suites yet.

      And while personally I agree with the commenter above you for personal reasons, I also think that the OP is missing that while the people who've ripped their js tool may have done so directly from their site, no one certainly has to any more: they can likely black-box something similar pretty quickly, at which point the author's DMCA moat is gone.

    • lewelove 9 hours ago

      > So is there a path to an ethical, viable business model for the author?

      Yes and no. An ethical business model for software in this world must be built on a long process of collecting good faith from customers, it just doesn't pay well enough compared to the ones that shatter said faith (adware, exploitation, dark patterns). I think the software moat will be more and more based on social capital. People are happy to pay for the software if they know for a fact that company/person behind it isn't being hostile to them. Look at Steam as an example of this. And you can always open source your code, and still make money through the means of good faith. Is it actually viable? I don't know. It depends on how much money you want to make.

    • prepend 9 hours ago

      I don’t want people telling me I can’t modify code sent to my machine to execute.

      Stopping me from editing out parts I don’t want to run seems odd. If you want me to run certain things, do it on your own hardware.

      This reminds me of the arguments against ad blockers. I don’t want people to force me to watch ads and not allow me to block them on my own machine.

    • criley2 9 hours ago

      I don't believe that "ethical" and "ad supported" are compatible. Harvesting our private data and selling it to the tech-dystopia to further curate profiles about our every move can never be considered "ethical", imo.

      From my perspective, those people who are taking this public client side code (not emulating any kind of server), and removing the privacy nightmare, are actually doing good for society. The software is more usable, more performant, and far more secure when they are done. The only harm is the authors ability to monetize.

      I don't think it's possible to have a fully client-side web product and be able to enforce strict guardrails on the use of the code. Regardless of ethics, it's just not feasible. What you give up by delivering the full source code to the browser to render is control over the source code.

      If the author wants more control over their source code, and easier monetization, they should compile a binary and distribute that. The guardrails protecting source code, duplication, and copyright infringement are much more clear. That's just the harsh reality of delivering source code to clients.

    • limagnolia 8 hours ago

      Charge upfront for development (patrons, sponsors, etc) /and charge for support and training resources. Open Source the code.

      That is my preffered business mkdel for software development.

  • p-e-w 9 hours ago

    > Copyright as a concept applied to code was always an awful idea

    That may well be, but as long as that concept exists in law, I sure would like every developer to be able to benefit from it equally, not just Microsoft and Adobe.

  • Roark66 8 hours ago

    I disagree. I think someone can take this code and write their own based on it. Not use his verbatim.

    At the end of the day the fact many people abuse IP laws doesn't mean there are no legitimate uses.

  • epihelix 6 hours ago

    > Copyright as a concept applied to code was always a god-awful idea, DMCA especially. And for JS served on the open web it's plainly comedic.

    Why is it comedic? All of my own code is open source and freely available, but protected by copyright -- namely via the GPL. Copyright is what helps ensure that we retain open code, and ensures that it propagates openly.

    How much further along the enshitification path do you think Android would be, if Google wasn't bound by the GPL in so many areas? Copyright with code is not only fair (why on earth would creating code be different to creating anything else?) but it is what keeps so many things free and open.

    • samatman 3 hours ago

      Hard question to answer. If there were another phone operating system, built on a combination of permissive and proprietary software, from a company which notoriously avoids 3.0GPL like the plague, and minimizes use of 2.0GPL whenever possible, then we'd have a fair basis of comparison.

      Guess we'll never know.

    • zelphirkalt 1 hour ago

      I think GPL was though of and is an answer to the idea of copyrighting code. If there was no copyright for code, there might not be any copyleft license. If we were all allowed to freely copy and modify and redistribute etc., then there would be no need for licenses enshrining these rights.

MisterMunchkin 10 hours ago

It's inevitable if your entire product is statically hosted and pulled into their browser. They didn't even need AI to do this, they could have just done it by hand anyway.

handoflixue 22 hours ago

Regardless of what you do now, I think you should be prepared for the upcoming reality that LLMs are going to be able to reproduce software, feature-perfect, in a way that does not currently violate copyright law.

Right now, the settled law is that such an LLM reproduction is 100% legal.

If you really want to protect your software in the years to come, you might have to seriously consider starting some sort of popular political movement to address this issue in copyright law.

Current models can already do a full reproduction of anything with source code available (e.g. JavaScript...), and there's already been some poor-quality Photoshop knockoffs.

  • tgma 21 hours ago

    > popular political movement to address this issue in copyright law.

    Or perhaps the people should admit that copyright, an artificial construct which is not rooted in natural property, was inherently broken and is not (or at least no longer is) a net benefit to the society and simply adapt around it.

    • theturtletalks 21 hours ago

      I was watching a video talking about how a world before copyright allowed innovation to spread quickly and allowed people miles away to iterate faster. Even if LLMs reproducing feature perfect software is deemed a copyright violation, people will just do it privately and use the software themselves.

      I’m personally waiting for LLMs to get so good that I can make music and movies based on my favorite ones. I probably could never release it to the public, but being able to make it and enjoy it myself would be amazing.

      • verdverm 21 hours ago

        There is something similar happening in the game modding communities. One of my favorite streamers had claude write a little mod to change the UI of KSP so it kept with the larger fanciful theme of the game, over being so sci-fi-ish. He didn't like, he changed it, he's probably not going to release it because of sensitivity in the broader gaming ecosystem.

        I have agents maintaining several patches to my main tools, not forking, not sharing (some have no interest), personal adjustments

        • tancop 15 hours ago

          > he's probably not going to release it because of sensitivity in the broader gaming ecosystem

          There is basically zero pushback to generated code. All the crazy Minecraft in GTA type mods that came out in the last couple weeks are obviously vibe coded but no one cares because they play good and surprisingly bug free.

          If he put in AI visuals as in generated textures then it's different, because that's way more visible and gets labeled as slop immediately. There's also the (accurate imo) perception that AI is taking artists jobs against their will but coders adopted it on their own and benefit from it, so using it for code is ethical from a labor rights POV.

          • verdverm 8 hours ago

            I believe it is a lot closer to CSS, some images for buttons that needed inverting, closer to dark mode

      • tgma 21 hours ago

        Another thing that can help contextualize this phenomenon is mix tapes, which are fair use in the US.

        Modifying/modding/remixing software was simply not as feasible as music, but LLMs made it possible.

      • mschuster91 14 hours ago

        That world worked because the ones doing the research were either self-sufficient hermits (often self-sufficient by necessity as they were outcast for "being mad"), financed by the Church or financed by a rich person (usually the fiefdom's ruler, sometimes independent wealth).

        Copyright, patents and IP are the evolution of our (Western) way of converting research into a form of financial investment.

        • ButlerianJihad 14 hours ago

          Patronage and support of the arts (and sciences) was a great value proposition for Churchmen in old times. You could commission works of music or sculpture or stained glass or what have you, and these were of course well-fitted to be installed or performed in the confines of your church and serve the liturgy. So they were collective goods that were enjoyed by many; they attracted locals and they beautified their surroundings, and they encouraged pilgrimages and stimulated income if you could become particularly distinguished and attractive, based on the beauty lent by your artisans and artists.

          And a big church could employ lots of them, and thereby stimulate the economy. It seems that the Baroque Era and churches crammed to the rafters with art, may be an artifact of a very good job market for those architects, craftsmen and artists!

          Yeah... you could copy some sheet music and share it around, but it still required skilled musicians to perform, play and sing it. And nobody was taking photos or uploading JPEGs of your art and sculpture, so it was fairly locked-in that people needed to visit, and see it in context. So it stood to reason that you could probably reconstruct Noah's Ark from the fragments of True Cross that were circulating around Europe... and how many fingers did your favorite saint really have?

          Copyright-free church economics have sort of fallen apart since then. However, museums, arena concerts, theaters and the rest, they have all taken pages from the Church playbooks. The fact that a church can still draw in hundreds for a show with great production values, every week or daily, seems dull and unremarkable now, but a good rock concert or museum collection can evoke the same "goin' to church" fervor in people who like that kind of stuff.

    • account42 14 hours ago

      Only if I as a human being get the same rights to e.g. Microsofts code as they get to mine via legal trickery in your world.

      • CamperBob2 5 hours ago

        You do. Just point the LLM towards windows.exe and tell it to party on.

        Won't work this year, but it probably will next year. Copyright is done.

    • handoflixue 34 minutes ago

      My one big issue there is that "adapt around it" tends to look like cryptic black box "Software as a Service" because that gives you a solid moat against competition / reproductions. I would like to be able to pay for software whose function is wholly transparent to me.

      That said, I mostly end up using open source for the same reason

  • 14u2c 21 hours ago

    > Right now, the settled law is that such an LLM reproduction is 100% legal.

    How so? Interfaces are not copyrightable, but that it not the same as dissecting a js bundle and copying the implementations. Are we sure these LLM are keeping sanitary habits there?

    • verdverm 21 hours ago

      if you've used any Ai in your own code authoring, copyrights may be completely out the window

      several courts have ruled Ai output is not copyrightable, I am unaware of any co-authored cases

      • abrookewood 21 hours ago

        That doesn't top people producing copies though, just trying to copyright the copies.

        • verdverm 21 hours ago

          it also means that you cannot claim copyright against copiers, the context here being the original has had Ai involvement in the development process

      • kube-system 16 hours ago

        If you only used the output of an LLM, then you don’t qualify.

        But, the use of LLMs is not disqualifying. To qualify for copyright protection your work simply must have a sufficient degree of human authorship.

        However this is just about protection, not infringement.

        If you use an LLM to generate something and that LLM just happens to output something that another human wrote, you may be liable for copyright infringement.

  • nathanlied 21 hours ago

    I feel like I need to nitpick a little: Models don't need source code available to reproduce software. See all the "full decompilation" projects cropping up. There's no putting this genie back in the box, because LLMs can also "refurbish" a project enough that it ceases to look like the original. People don't bother now because they don't have to, but in a world where they'd get hit with copyright notices, they would.

    • handoflixue 40 minutes ago

      I will say that a lot of the "full decompilation" projects popping up are honestly crap - some are good, but a lot of them just build something that makes for a good screenshot or promotional video.

      I'm not convinced we are actually at the point where something like Photoshop is trivial to rebuild. That involves a lot of manual QA and the expertise in actually knowing how everything should work.

      That said, give it 6-12 months and I won't be surprised if they can one-shot "create a future-complete clone of Photoshop, make no mistakes"

  • kube-system 16 hours ago

    > Right now, the settled law is that such an LLM reproduction is 100% legal.

    Where did you hear that? Because it is 100% untrue and is the opposite of current legal guidance from reputable legal expert

    • handoflixue 38 minutes ago

      There was a major lawsuit about this involving Google vs Java years ago. Copying code might not be legal, but an LLM can use the application, learn how it works, write unit tests around that, and then fill in code that passes those unit tests.

      The current fun loophole is to have the LLM decompile the existing code, build unit tests around that, and then have a different LLM model build the code that satisfies those tests.

      Either way, you can absolutely get a "clean room" result from an LLM.

  • codingdave 1 hour ago

    > the settled law is that such an LLM reproduction is 100% legal.

    My understanding was that re-invention without copying any code is legal. But scraping code from the browser and re-using it is not. I'd love to know how that plays in the courts with LLMs, as their entire model comes from copying code as training material, not writing new code from scratch.

    • handoflixue 36 minutes ago

      Sorry to have been unclear - I did mean "clean room". But an LLM can easily jump through the loopholes currently required for that.

      Regular humans train on copying code too (Stack Overflow, etc.) so unless they were trained on that specific codebase, I really doubt you have any sort of legal standing. And given how little compensation the authors got when their work got trained on, I wouldn't hold out hope for a big payout even then...

anilgulecha 18 hours ago

Can you post the actual link of the repo? You'd get responses with more context.

You had commented on the photocraft post prior, so if it's that, then it's a bit muddled. It's a LLM based re-implementation and not a copy of the code made open. So the argument would be weaker there, and you'd really need specific code samples to make a case of copyright infringement. Photocraft not "piracy" as is normally understood, which is the exact same binary, optionally with the license protection removed.

jdlshore 22 hours ago

It sounds like you might have a case for copyright infringement. Resolving the situation yourself has failed. Your next step is to talk to a lawyer.

msalihb 12 hours ago

I use photopea for years and really respect what you did. I disabled the adblocker. I hope they remove that.

  • sen 12 hours ago

    Yeah I’m a huge fan too and pay for a subscription. It has basically fully replaced Photoshop for me for at least a few years now. Between Inkscape and Photopea I haven’t touched an Adobe graphics app in years.

  • 2b3a51 12 hours ago

    T.I.L. about photopea, and I have disabled Ublock Origin for the site. I see a static 'slide show' column of non-video adverts on the right hand side of the screen - about 10% of screen width.

    Best of luck with the copyright complaint.

jameshilliard 21 hours ago

> Thank you for submitting a DMCA takedown notice. We've reviewed the information you've provided, and based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201.

Did they actually republish you code or were they just creating wrappers that download/cache the code from your website to run locally?

B4uler5 1 day ago

Sorry this happened to you dude. I don’t want to be harsh but, out of the crimes ignored in this era of AI clean rooming, book destroying distilleries and a despondent ostrich adjacent legal system you do seem to be one amongst a deluge of cheated individuals.

Hope you manage to get it sorted but I have no idea how that would go down at this point. I’m sure at least one of them could claim they copied it off the other ones and then you’re shit out of luck.

  • seanw444 22 hours ago

    This really is a terrible timeline.

binlog 22 hours ago

Yes you need a lawyer. You may not have filed the DMCA request correctly. You may not be understanding the law correctly.

aetherspawn 1 day ago

I think what you want is a legal avenue, like Trademark, Design rights, or patent.

If you have one of these, it’s possible that GitHub would honour it if you go via a lawyer.

BSVogler 15 hours ago

I am in the same situation where people are hosting copies of the software for commercial use in companies. Even as big as Tencent. That is not allowed with my license and they also went to remove the code that does the license check on application startup. GitHub’s response so far: “please give an explanation how they can become conformant so that the users can fix this.”

swframe2 6 hours ago

<Naive>

Run the code you want to protect in a cloud function. Cache the user data on the server; modify it on the server, send the diffs to the browser.

</Naive>

<MoreNaive>

Any product that agent can generate from a prompt or reverse engineer will be cloned.

</MoreNaive>

<MostNaive>

Solve problems that make your life better even if cloned.

</MostNaive>

SeriousM 13 hours ago

A talk with a lawyer would be advised. But this is money you may not want to invest. You could just go on, keep your product improving and proof this way that your solution is more worth than the copycats out there. You just realized how it is to be a valuable target.

throwawayffffas 12 hours ago

> What do you think I could do?

Hire a copyright lawyer.

Start going after the people that run this as a service, for both copyright and trademark infringement (you have a trademark for photopea right?).

lrvick 22 hours ago

I was like oh cool... until you mentioned the ads.

I would not fork or re-release proprietary code. I would ask my LLM to write a very rigorous end to end test suite for your tool, delete all the code, then have a clean context LLM re-write the code to pass all the same tests. Then I could publish it under an open license.

Ads are a cancer, and it is a matter of weeks before someone does the above where you have zero recourse.

I suggest open sourcing the code properly without ads yourself before someone does it for you. If you do that someone might donate to you instead of paying for the tokens to clone your work.

Software is no longer a moat and DMCA means nothing anymore.

  • lofaszvanitt 22 hours ago

    How are you supposed to make a living without ads in this "ecosystem" or should we say walled garden?

    • Madmallard 21 hours ago

      You aren't. People aren't going to be able to make a living in software anymore, unless they work for a corporation. And even then, that's disappearing as well.

      • lrvick 21 hours ago

        When the whole industry manually punched machine code into punch cards, people were threatened by assemblers taking their jobs, and then later by compilers, and now by inference engines.

        The real engineering work that will always be paid for is identifying problems and testing solutions to see what solves the problems.

        The substrate in which we use to do that will change, but the job will endure.

        Those that just do what they are told however, yeah they are SOL unfortunately.

        Creative problem solving is the only skill that will matter anymore.

        • lofaszvanitt 21 hours ago

          And how many companies need creative problem solving? Way less and less. The problem is the moat is getting higher. Name any other profession that is kneecapped worse than by the free open source movement and the like. Meaning you can't monetize what you create. Or the usual ways are non-conformant, dictated by the corps and their mindless followers.

          • lrvick 21 hours ago

            Almost anyone learn anything they want now. This all cuts both ways.

            If security is a solved problem then anyone that wants to teach themselves enough can move to trying to solve disease, until disease is solved, then we all move on to building enough robots to mass produce enough food to solve world hunger and shelter... and once the needs of everyone on earth are solved at an ever cheaper price until it is free... then I guess we do whatever we want.

            • ipaddr 15 hours ago

              Only way to earn a good living is to pivot to solving diseases for a few years until robots solve world hunger and shelter. Then we can do what we want without the money to do it?

              • Madmallard 13 hours ago

                Doubt any of this is going to happen.

                • lrvick 3 hours ago

                  Most positive changes in this world happen because of the tiny subset of the people delusional enough to believe they can do so that also happen to be correct.

                  I feel like trying to better humanity, even if I fail, is a better use of my time than simply saying nothing can be better and giving up. At least by failing well, at worst, the next delusional person can carry the work forward learning from my mistakes.

                  It is going to be a slog, likely over multiple generations, but one worth the climb.

                  • Madmallard 1 hour ago

                    "I feel like trying to better humanity, even if I fail, is a better use of my time than simply saying nothing can be better and giving up. At least by failing well, at worst, the next delusional person can carry the work forward learning from my mistakes."

                    If you have the capacity to do that, I.E. a multimillionaire, then sure.

              • lrvick 12 hours ago

                I want a post scarcity society where money has no meaning.

                Capitalism is just a bootloader to get us there.

                • bluefirebrand 10 hours ago

                  I want people like you to get your heads out of the clouds and realize that post scarcity is never going to happen in our lifetimes

                  • lrvick 6 hours ago

                    Who said anything about our lifetimes?

                    Humans once built things to benefit society over multiple lifespans.

                • MentalM 6 hours ago

                  There will always be scarcity, it is unsolvable problem. Humans needs can't be met, people will always want more.

                  • lrvick 3 hours ago

                    If everyone has unlimited access to food, shelter, medicine, and knowledge then we are left with a tiny subset of compulsively competitive people fighting each other to acquire new forms of entertainment. I would pick that world over this one.

        • Madmallard 17 hours ago

          People bring up this argument again and again as if AI is somehow the same as everything else.

          It's not. The economic landscape is also entirely different from before as well.

          • lrvick 12 hours ago

            AI may be the biggest change to society since electricity, but fundamentally we survived that transition and on the other side the baseline quality of life is much higher now. This one stands a very good chance of ending the same way.

            • Madmallard 1 hour ago

              Doubtful when we're flying toward hyperinflation because of government overspending with zero care for their citizens.

              Doubtful when stock prices go up because companies lay off/fire employees.

              Doubtful when hiring foreign workers for cheap is strongly preferred over their own citizens.

              If you're already a millionaire now invested in tech and S&P500 and have property maybe you'll be alright and maybe you won't agree with this perspective, but my perspective applies to the vast majority of people.

    • lrvick 21 hours ago

      I was a software engineer and pivoted to full time security about 10 years ago. Security will be in demand for a while longer I selfishly suspect.

    • verdverm 21 hours ago

      Adobe buys ads rather than sells them, is that correct? How are they making money?

      • saaaaaam 17 hours ago

        Enterprise customers and dark patterns.

    • prmoustache 11 hours ago

      Supposedly like any software company selling their product or a service.

      If ad was the only way to get money, there would be no product/service to sell anymore and thus...nothing to advertise. It just cannot work that way.

    • fg137 10 hours ago

      As a reminder, this is the year 2026.

      Photopea is lucky that it has a decent amount of revenue. But that's an exception, not the norm. Generally speaking, for new software, the business model of desktop, client-only software hasn't worked well since late 2010s at least, and nobody should expect to run a viable business like that today. There are very few applications you "install" on your computer that doesn't require native capabilities in some way.

  • kqp 17 hours ago

    Hey buddy, you’d better be careful what you post on a public forum. Sooner or later somebody’s gonna ask their own personal LLM to write a comprehensive test suite for how you respond to comments and situations, move the mouse cursor upwards and to the left to click a button there, and recreate you as legally their property now. If I were you I’d gimme money gimme moneyyyyyy before my big LLM here teaches you a lesson the hard way.

    • lrvick 12 hours ago

      Please rip me off if you can! I would be thrilled. I open source 100% of my work and if people plagiarize it and the net result is my work and ideas positively impacted more people, then that is an outcome I am proud of.

  • klntsky 17 hours ago

    True. I understand the author on the emotional level, but the fact that a lot of work went into the product does not mean that it is that valuable. The author should focus on making the product better - unfortunately (for them) that means inventing a new business model.

  • fg137 10 hours ago

    Someone speaking the truth.

    A closed source, client-only "desktop" application, especially a web app with obfuscated/minimized JavaScript code, has no real copyright protection these days. You either sell ads, sell it to enterprises, or if you are lucky enough to be able to pull it off, sell a subscription. Not putting the logic on the server in the first place means everything is basically public knowledge.

pdutt111 8 hours ago

just move crucial bits in another language and use webassembly. so good section of your code is in compiled binaries hence blocking anyone stealing your IP. also at the moment they just change some bits I don't think it'll be long before they can just recreate a new project with different code but with exactly the same functionality and then you got no protection afaik(although not a lawyer so not 100% sure).

  • onlyrealcuzzo 8 hours ago

    > just move crucial bits in another language and use webassembly. so good section of your code is in compiled binaries hence blocking anyone stealing your IP.

    Can't you just steal the entire WASM code just as easily? I mean, I guess if the ads are stuffed in WASM that becomes a problem. But LLMs are pretty good at reverse engineering. I can't imagine it would be too much effort to get them to take the ads out, or to replace your ads with their ads.

  • gpugreg 8 hours ago

    LLMs can decompile assembly code quite well these days, so I doubt that WebAssembly will be a hurdle.

maximegarcia 6 hours ago

question: the code on Github is an issue (plenty of answers on that), yes, but is people hosting copies of your service a bigger issue? In other words, they are probably similar people that do it without publishing on Github...

anilakar 13 hours ago

I accidentally stumbled upon malware disguised as Roblox hacks some three hours after the repo was created. It took Github 25 days to take it down. Granted, the initial automatic reply admitted they were "experiencing high volumes".

nchmy 12 hours ago

Sorry to hear this is happening. One thing that might be helpful is to port it to another language and build as wasm. Agents are pretty good these days at stuff like this might even end up being faster.

conartist6 8 hours ago

Also get ye some trademarks. Make sure your logo and branding colors are trademarked in combination with the name Photopea. Use the logo and branding colors more places.

It won't stop AI thieves cold, but now they'll be in violation of two kinds of law unless they do a bunch more work to rip out all the trademarked branding.

Finally, move beyond ads as your business model.

An ad blocker removes the ads from your website, and still leaves you paying to host the traffic. In a way it's worse for you than what unauthorized mirrors are doing. You're seeing that there's unmet demand for what you are offering, so my advice is: figure out how to capture that demand. Why aren't those people taking the deals you're offering them?

I took the liberty of disabling my own ad blocker to do a little research and HOLY COW THESE ARE BAD ADS.

Let's lay out the problems:

- Something is horribly mangled in the ad loading code. The ads flash in and out of existence, and cycle through at breakneck speed, ~5 seconds per ad. Between the flashing in and out and the flashing different ads, it is not possible to do serious work with this going on.

- Many of the people who don't have a photo editor on their device are using touchscreen devices. Many of those people are right handed. For them the actual photo editing tools would be largely impossible to use without accidentally clicking a giant ad which takes up the whole right side of the screen, at which point they would no longer be able to edit photos. Once this happens to you 5 times or so I imagine you start to get very angry.

- Because the ad doesn't fit into the UI at all, you're wasting huge amounts of the screen and impacting productivity proportionately.

So I guess my final advice is: if you don't respect your users, I don't know why you would expect them to respect you. Offer a better deal and more people will take it.

  • conartist6 7 hours ago

    As for how to do better ads, I imagine the best kind of ads would be those where you have a pre-existing relationships with providers of services: photo printing or cloud storage or whatever. When you send them customers who buy things, you get paid. You can then make the ads feel well-integrated into the product, like they're there to help the user. Fewer people should then be willing to go to the trouble of tearing them out. As a bonus if the promotions are built directly into the product, ad blockers won't block them either!

randyrand 14 hours ago

Wow, was not expecting this to be about Photopea! What an amazing piece of software I used it all the time! Less with AI these days, but still lots!

bityard 9 hours ago

You're asking HN if you should contact a lawyer about a legal situation?

ShinyLeftPad 8 hours ago

File a copyright takedown, that's a clear cut violation.

AbuAssar 7 hours ago

Move as much js code to compiled wasm

philipwhiuk 12 hours ago

By the way, are you really allowed to deeplink to Imgur to host most of your templates?

(I only noticed because your site is not blocked in the UK but most of the templates are.)

kasajian 17 hours ago

On the bright side, I now know about your product. Had never heard of it prior to this.

WhereIsTheTruth 8 hours ago

It's funny how Microsoft era github became the home of pirates and thieves

prologic 9 hours ago

Have you considered not serving ads on your website and making it more accessible to discourage those from wanting to tip it off and strip the ads? I can tell you from honest experience, if I were a user of your software/site (which I'm not) and it had ads, I'd be dropping them on the floor pronto (probably with AdGuard). I hate ads, I despise what we've done with the Web/Internet with all shit Advertising and Tracking shit™

  • cpach 9 hours ago

    I don’t like ads either. So I just paid for a local image editor and use that one instead. The developer of the product gets paid, I get a great ad-free image editor.

ianberdin 1 day ago

I personally know Ivan. For many years of his life, every day, he programmed algorithm after algorithm in this complex online photo editing tool. Essentially, he devoted half his life to it. And now, when someone has literally stolen his work, nobody is reacting. And that's terrible. I think it's absolutely terrible. GitHub should respond to this.

I've seen people on Reddit writing things like, "Come on, what's the big deal? AI can write any code now." I disagree. There are hundreds of thousands of lines of code here, very complex code, which even AI wouldn't be able to write on the first try or in a single day. So this person stole this code from Photopea and built a product on top of it.

  • sneak 1 day ago

    Copying isn’t stealing. We settled this in the 90s.

    • flourish_dev 23 hours ago

      Yeah, this bodes well for my meditation app frontend I'm going to release on GitHub. It should be fair use ish but it does seem GitHub is fairly friendly anyway.

      • wafflemaker 14 hours ago

        Headspace without being tracked and having data brokers cross reference "anonymized" (sic! word wasn't in keyb. dict) info on when I meditate, using which program etc.?

        Headspace updated it's privacy policy info recently, which got me to have it checked with an LLM. And it turns out that what you're doing on $100 per year meditation app is still being sold to anyone willing to pay. Using headspace lost it's charm. I wonder if Andy ever agreed to this.

    • otterley 15 hours ago

      The word “stealing” isn’t limited to physical objects.

      • DaSHacka 14 hours ago

        I would agree, should you `rm` the copy on the server after having copied it.

      • calgoo 13 hours ago

        Thats what the copyright lobby wants you to think, but honestly, if i copy your digital item, im not stealing it as the original still exists in your possession. That you might infringe on content made by someone else because you copied them, sure but its not stealing.

        • otterley 8 hours ago

          What do you do for a living?

  • binlog 22 hours ago

    Do you have the same stance on using adblockers when browsing the web?

  • mingus88 22 hours ago

    This is a very old problem. One of my first commercial programs was a wordpress plugin and as you know, you just distribute the PHP source code in a zip file and there it is

    You will never sue your way out of this. Piracy will always exist. GitHub will respond to a legal notice but whack a mole is the game and legal notices cost money

    The solution in the WP community at the time was variations of the plugin as a loss leader to get revenue with support or to leverage community visibility into larger contracts for work or hosting the platform for others.

    If your business model depends on your code being a secret, JavaScript is not a good play. The business model needs to enhance what the code offers since it’s basically a commodity now

    • TiredOfLife 17 hours ago

      Aren't all Wordpress plugins GPL due to wordpress being GPL?

      • SwellJoe 16 hours ago

        No.

        • RobotToaster 14 hours ago

          Yes.

          • SwellJoe 4 hours ago

            There exist many WordPress plugins that are not GPL-licensed, or plugins that are ostensibly GPL but are merely wrapping things (either code or APIs) that are not GPL, which isn't exactly a compliant use.

            Whether we like that is not the question I was answering.

      • Tomte 16 hours ago

        They need to be, but many plugin developers simply break the GPL.

      • 0x073 12 hours ago

        If they just use the api to create the plugins, no. (It's like Google vs oracle and the java API)

        • RobotToaster 11 hours ago

          It's the position of wordpress that all themes and plugins are derivative work https://wordpress.org/about/license/

          My understanding is because of the way PHP works all plugins are directly interacting with the wordpress code.

          • topham 10 hours ago

            Wordpress does absolutely nothing to enforce this, so their position on the matter is irrelevant.

            Commercial plugins are a thing, next.

          • 0x073 4 hours ago

            I understand, but if I create some code that use no wordpress code and only API access and don't ship it with wordpress, they can't enforce a gpl licence for my code.

      • mingus88 5 hours ago

        Sure but developers would still add licensing checks, hosting some dependency offsite, or other obfuscation to try and force people into paying for the plugin

        It just doesn’t work. Anyone who wants to will take it. I don’t see this problem going away

  • berofeev 17 hours ago

    I agree. It's so disheartening to hear Ivan in interviews talking with passion about what he built. And it's truly impressive!

    But wow, how do you stand a chance in stopping anyone when your code is all there freely available in the browser

  • croes 16 hours ago

    > AI can write any code now.

    Because it is trained on code of people like Ivan

  • Uptrenda 13 hours ago

    AI did this to every developer in the world and nobody cares. This just confirms to me that software engineers are the biggest cucks that exist right now.

  • topham 10 hours ago

    If you think an AI can't reproduce this without it being a copy of the code you are sadly very very mistaken.

    I've had an AI reproduce astronomical formula functions without difficulty in whatever programming language I want. Graphical algorithms aren't even a challenge.

    Might be time to reconsider the business model entirely, because Pandora's box is already opened.

busymom0 21 hours ago

I just wanted to comment to say I love Photopea and have been using it for 6 years I think. Best piece of software imo.

kiririn 9 hours ago

I'm surprised Github even respond to DMCA claims rather than passing the buck like they do for GDPR*. Perhaps they are more respectful to home laws

*They wash their hands of any GDPR deletion/anonymisation requests, instead passing them and your identity documents to the repository owner!

anon48293 16 hours ago

It is not illegal to build a service with the same functionality.

So you are going to have to prove their code is a copy of yours, not just a copy of the functionality.

In Google vs Oracle, APIs also aren’t necessarily copyright able:

“So long as the specific code used to implement a method is different, anyone is free under the Copyright Act to write his or her own code to carry out exactly the same function or specification of any methods used in the Java API. It does not matter that the declaration or method header lines are identical”

To sum it up; get a lawyer.

anonym29 10 hours ago

I enjoy and use photopea just as much as everyone else here, but isn't the whole premise of photopea to offer a near-exact reproduction of photoshop's UI/interface and functionality, such that users who might otherwise be paying Adobe customers just use photopea instead?

This reminds me of LLM companies scraping the entire internet and destroying millions of books to scan them in bulk quickly and then complaining about others performing distillation attacks against their models.

It's fine to be unhappy about people coming to you with complaints about forks of your software, but if the premise of your project is "we made a near perfect clone of Photoshop so you don't have to pay for it", haven't you kinda ethically ceded the right to complain about other people copying your software, even if you managed to stay within the confines of copyright law?

If you're building on other people's ideas and work, don't you owe the world a duty of reciprocity in openness?

  • bitwize 10 hours ago

    Indeed.

    Bring back look-and-feel copyrights and the Whelan interpretation of software copyright. Programmers have gotten away with stealing the patterns for entire programs, producing identical clones of another company's valuable IP, for far too long.

    I have a feeling that Whelan is going to become relevant again as judges realize that people are using AI to copyright-launder major applications and games (a practice for which I'll coin the term "sloppylefting"), effectively stealing them in a way that cannot be prosecuted using the current very strict interpretation of copyright law with respect to software.

rvz 1 day ago

> What do you think I could do? Do you think I should look for a lawyer to deal with it outside the digital world?

Use a trademark.

  • IvanK_net 1 day ago

    Wow, that might actually work, thanks!

    • fakedang 22 hours ago

      First of all, thanks Ivan! Happy user of Photopea.

      Second, the trademark will help you against the masqueraders, those copying your tool and the Photopea brandmark. That will help with customers complaining about some other modified product. It will not help in case you find someone copying your codebase and putting it out in the open under a different name. For that, you'll need a copyright.

      Doing both of these might be expensive but gives you complete legal standing. Companies will have no choice but to take down the copies.

      • LoganDark 15 hours ago

        It will allow them to force modified forks to stop using the Photopea name in a way that confuses users and results in delusional support requests.

  • nixrobot 1 day ago

    How will that help? Trademarks do not protect code - only logos, names, brands. And brands are easy to remove.

    Something else is needed. If the code is basically open, then there is no technical protection. Remove tens of those repos - hundreds might appear.

    • fg137 10 hours ago

      Even if the author only wants to protect the "Photopea" name, good luck going after infringements if you are not a giant corporation with resources.

modzu 2 hours ago

hey there. fellow indie dev here. i feel you, i see copyright and ai slop ripoffs on the daily. in fact i used to be most upset seeing my opensource code show up in much bigger commercial projects unattributed (looking at you microsoft) but im here to tell you the real answer: you have to compete. you have to compete against the slop and the clones just like youre competing with the original ps and the gimps and the kritas already. it doesnt seem fair, it seems harder, and it is. but thats the truth. ai is out of the bottle. you can still make a better photopea than some dimwit ai and the loser trying to publish their clone, because you think about and obsess over and care about your product way more deeply. that manifests. and you might say why obsess when it can just be copied. and now you sound just like metallica did in 1999. welcome to 2026

pluc 13 hours ago

It wasn't stolen or copied, it was used as inspiration by AI. Good luck fighting that.

ranger_danger 21 hours ago

> based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201

Sorry GitHub, that's not for you to determine, as you are not a US judge. They should never have replied like this IMO and this behavior opens them up to liability for not properly handling DMCA procedures.

Proper DMCA 512(h) notices (assuming OP's was proper) require the host (github) to remove or disable the content first without even attempting to verify the claims.

Then the repo owner has a chance to challenge the notice. If they choose to do, they're basically required to publicly doxx themselves first, by nature of just going through the motions of the judicial court system.

If there was no challenge after a set period of time, then the content stays down.

If there was a challenge, it stays down until a court decides what happens next.

  • verdverm 21 hours ago

    the musicians love it when their original work is DMCA'd by bad actors and YT takes it down and never answers the appeal /s

    two sides to the coin, we'll hear about how some evil corporation used their influence to have a legitimate project DMCA'd and HN will have the opposite reaction on that day

    something like "jury duty" from the community seems an interesting idea for a middle path, if we want better systems, we'll all need to contribute a little to making it so

    • ranger_danger 16 hours ago

      Requiring an independent jury decide the appeal sounds like a good idea to me, but good luck getting a law passed that forces it...

  • samatman 3 hours ago

    I am utterly fascinated that you copied and pasted section 1201 and then replied as if the string which, you, copied, contained § 512(h) instead.

    What happened here?

Razengan 15 hours ago

Oh jeez. I'm not automatically assuming that the Chinese did this, but Chinese IP thieves did crap like this for decades, and most of the victims were unable to do anything. There were posts right here on HN like "Chinese company stole my app/game" and with AI this will be an even bigger problem.

Meanwhile AI refuses to touch photos that contain anything that remotely looks like Mickey Mouse.

Shit was never on the Common Folk's side.

  • fuzzfactor 12 hours ago

    You're really pointing out a couple fundamental principles where growth has been able to occur one layer at a time over a nonsensical foundation.

    This doesn't lend it self to a sensible solution.

    There's no way that computer code should have ever had any legal similarity to entertainment properties like Disney characters.

    Plus so many people don't want to pay any attention to the way there's a big difference between entertaining software like games versus things which are needed before "machines" will even (barely?) run, or run more superbly which is not the same either.

    And there's no way any "rights" should exist for an extended period.

    Among other things these need to be corrected more so than ever (or AI will do it for us). The problem is it all needs to be sensibly reversed not gutted in one big shockwave. But AI is here to shock. It doesn't even take superintelligence, if the people who gradually caused the problem over the decades were below-average things would have come out better as long as their objectives were less predatory.

mistrial9 22 hours ago

you wrote a complete product in javascript, and people wildly copy the code?

My reply is that you now own a customer list, brandname and trademark, and that is about it.

verdverm 1 day ago

There are 100s of web based photo editors, paid and open source. How do you know they are taking yours, not someone else's or making their own with Ai?

I would imagine they all converge on common features and core implementation foundation

  • IvanK_net 22 hours ago

    There have been only two photo editors that fully support the PSD format: Photopea and Adobe Photoshop. When a new one appears, which fully supports the PSD format, from an anonymous creator, it is very likely a copy one of these two. And they usually name it Photopea-offline, etc.

    • verdverm 22 hours ago

      but does it actually fully support the PSD format or is it false advertising?

      This day in age, we need to verify ourselves

      Can you show us an example? How did you verify?

      • sampullman 16 hours ago

        The website is public, you can verify yourself.

        • verdverm 16 hours ago

          That's the original, where's the copy, specifically the one OP DMCA'd, which is supposedly not taken down...?

          I would think a github link would be easy to provide, sus that it hasn't been

          • Mashimo 11 hours ago

            I just searched "github Photopea-offline" and found one within the first 2 results. Uses "Photopea" name and logo.

            • verdverm 8 hours ago

              Why is so hard for people to post a link? If y'all are going to be making claims, post the links to back it up. Then show how the code is the same. If the original is online and the copy is offline, that would seem to indicate a material difference (without digging into both their code)

              This smells a lot like the Laya thing to me, especially with the astroturfing by friends and fans

              • Mashimo 3 hours ago

                I can post the link, but OP does not want to, so I decided to follow his request.

      • IvanK_net 15 hours ago

        These Github repositories contain copies of my JS files (identical JS - letter by letter), with a few lines deleted to allow running it on any domain.

        I wanted to discuss the behaviour of Github without giving these "projects" even more attention.

  • ChrisRR 12 hours ago

    > How do you know they are taking yours, not someone else's

    Because if the javascript source matches the source in the repo, then they copied it

    • verdverm 8 hours ago

      it doesn't sound like that though and we have no way to verify

Kivan_net 14 hours ago

Couldn't have happened to a nicer target.

penskymaterial 22 hours ago

You want to sue people for blocking ads? Did I read this correctly?

If you want to make proprietary software that's cool, but client-side JavaScript was a terrible choice. The cat is out of the bag.

There's a reason software for which you purchase a license key generally doesn't give you source code outside rock-solid legal agreements.

  • jffry 22 hours ago

    You did not read it correctly. Author stated that people are modifying and redistributing their code in an unauthorized manner.

    • penskymaterial 22 hours ago

      Did those people sign a legally-binding end-user license agreement?

      Because what I see is essentially "they're storing stolen property" but the burden of proof is on the author to prove it was, indeed, stolen.

      I imagine the bar for that is pretty high otherwise anyone could weaponize DMCA to target their competitors' repositories.

      • jffry 21 hours ago

        You seem to be thinking about "adblocker running in browser", since you brought up EULAs.

        That's not what OP alleges - they are saying people are redistributing modified versions of OP's copyrighted code. DMCA is an appropriate measure in such a situation, but it's unclear why OP's DMCA takedown was rejected by GitHub. Without more detail, it's hard to comment further

        • verdverm 21 hours ago

          one would think, if it is still up there, OP might point us at it so we can see for ourselves, right now it's "trust me"

  • bartread 22 hours ago

    > You want to sue people for blocking ads? Did I read this correctly?

    That is an extremely disingenuous and bad faith interpretation of what OP has said and I think you know it. You want to be edgy? Go comment on Reddit.

    OP is rightly frustrated that their copyrighted work, that they’ve been working on full time for over a decade, is simply being ripped off by people and GitHub refuses to do anything about it.

    • penskymaterial 22 hours ago

      Publishing source as client-side JS when millions are out there looking to rip you off at every turn is a losing proposition. And I think you know it.

      Shifting blame to GitHub is absolutely idiotic.

      Try removing locks from your doors in a high crime area (which is what the Internet is) then being indignant when the police can't stop all the criminals stealing your property.

      • cbarnes99 20 hours ago

        'losing proposition' is irrelevant. The law is clear in this case, and the law makes Github's obligations exceptionally clear. By refusing to act, if the DMCA notice was valid, Github is breaking the law and forfeiting their safe harbor status.

        • fg137 10 hours ago

          Are you a lawyer?

  • ChrisRR 12 hours ago

    No, you did not read this correctly

  • ryanascend 5 hours ago

    I'm a solo dev who just shipped my first iPhone app, and reading this is a good reminder of why I went the App Store route. My code ships as a compiled binary, so there's no source for anyone to copy and republish. I pay Apple's cut and complain about review delays like everyone else, but never having to file a DMCA takedown against someone reselling my own work is worth it.

    • samatman 3 hours ago

      Just replying that I vouched for this post, and to ask others to please restrain their pique and not flag it into oblivion again.

      This is a good faith contribution to the discussion, and frankly, the way things are going, the point it raises is something most of us need to consider.

pbasista 13 hours ago

I would suggest that, instead of trying to complain about the people copying your products, which I think is practically impossible to avoid, and even from your own experience preventing it has led nowhere so far, you should focus on making sure that your version of the product is the best one. So that the people will naturally use it instead of those repackaged versions.

> take the Javascript code from my website, remove all ads from it

I would assume that this might be one of the reasons why people are modifying and repackaging your product. I would suggest to remove that incentive. So that the people will have no reason to repackage your product because it has annoying features. And so that they could use it directly and be happy about it.

  • boxed 13 hours ago

    That's a weird take. It's like if your boss considers outsourcing your job to a country with cheaper labor you suggest stop asking for a salary.

    • 1718627440 12 hours ago

      Which to be fair, would maybe actually work, and there are political positions that want to achieve such an economic system. Not that I would necessarily agree with them.

    • pbasista 12 hours ago

      I do not understand how what you have suggested could be considered as an appropriate analogy.

      No one implied that the author should offer their product for free. I merely suggested that they need to focus on other aspect of their product rather than the mechanical software parts because they can no longer be the differentiating factor. Precisely because they could easily be recreated or copied.

      • boxed 5 hours ago

        I replied to a comment suggesting removing the ads.

    • fg137 10 hours ago

      If you can't demonstrate there is value in keeping you vs outsourcing the job, well, that's naturally going to happen.

      I say that as someone who thinks about this almost every day.

  • robotmay 13 hours ago

    But he could spend months adding a feature just for someone to spend 10 minutes running it through an LLM and shoving it up for free on GitHub.

    • pbasista 12 hours ago

      Of course.

      I think that the differentiating factor must be something else than the software product feature. Because that can easily be copied or recreated.

      It can be e.g. the customer support where customers will be listened to and will have their suggestions and requests implemented as features.

    • fg137 10 hours ago

      That's why you don't put your logic in the client, especially not JavaScript.

      Arguably Photopea made a mistake, and now they are paying for it.

      They can fight, but it's a losing battle.

  • AlienRobot 10 hours ago

    >you should focus on making sure that your version of the product is the best one. So that the people will naturally use it instead of those repackaged versions.

    Do you have any concrete ideas for how to do this or are you just saying this to defend piracy?

sourcecodeplz 13 hours ago

Wow the entitlement is strong on this one.

Wonder how many even built a popular free product supported by ads?

It's quite difficult and you need to provide even more value than a paid product (if that makes sense) for users to come back constantly.

There is nothing new now with people copying software. It's just that much MORE of the masses have access to this now than before.

And thus thieves multiply exponentially.