Tell HN: GitHub refuses to remove cracked copies of my software after a month
491 points by IvanK_net a day ago
491 points by IvanK_net a day ago
I am a developer of https://www.photopea.com, a popular photo editor that runs in a web browser.
Many people are asking AI models to take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download.
There exist tens of such repositories on Github. I want my website to be the only source of a stable version of my program Photopea. I even received emails from people complaining about something in Photopea, and it took several emails to figure out that they are not using Photopea.com (so it ruins my reputation a little).
I reported it to Github on the 4th of September 2026: https://www.photopea.com/g/XKoqqIGv
Today, a month later, I received this response:
Thank you for submitting a DMCA takedown notice. We've reviewed the information you've provided, and based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201.
What do you think I could do? Do you think I should look for a lawyer to deal with it outside the digital world? I really doubt that a real person ever looked at my report, and they probably send this response automatically to 99% of people.
IP lawyer here - I can't give you actual legal advice because you aren't my client, but generally, you have two options here, neither of which will be surprising, or very satisfying: 1. Pay a lawyer or firm that specializes in this sort of thing to play whack a mole for you 2. Accept it as normal losses and ignore it. Contrary to others claims here, it is not a 500/hour thing to do #1 when dealing with firms that specialize in this. it probably would be if you just hire a random one-off IP lawyer to try and deal with this particular instance. Trying to deal with it yourself will be increasingly frustrating and time wasting for you. You will also never be able to prevent someone sufficiently motivated from doing stuff like this to your software. Unless you want to spend your time dealing with those folks instead of building the software, you should hand this part off - it's not a good use of your time, value wise. Put another way: most companies farm out processing of this sort of request to high volume low cost processing teams. Or AI. Or both. For you this is an important one off. For the person processing it it's one of a hundred tickets they are handling today. You are not going to get very personalized attention and consistency. I don't claim this is how it should be, etc. I simply claim this is how it realistically is. It would practically require legislative change to have a different thing happen here and while interesting to discuss, that seems outside the scope of your questions, which seemed more practically oriented What I am hearing is “there will be no justice here for you.” The bad guys are winning, because the good guys have no legal recourse. The only practical solution is vigilante justice, but that makes you a bad guy. In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice? Let's separate criminal and civil here, because this is all civil law. Civil law systems largely aren't about "good" or "bad". Justice there isn't "good guys win" and "bad guys fail". It never has been. It's about trying to reasonably resolve disputes. That's all. Civil legal systems were created not to enforce morality or social order, but instead to formally resolve disputes.
The system is pretty good at doing that. It will never resolve all disputes, let alone resolve all disputes in an "optimal" way (for any possible definition of optimal you come up with). It only tries to do a reasonable job of it. If your expectation is that the law will stop "bad" actors from acting "badly", i think your expectations are out of whack. Yes it gets tried, but it is a fairly miniscule portion of the system overall, and generally not a very successful part of it. It's also remarkably recent in the history of legal systems. It is a quasi-political thing that the legal system simply isn't good at dealing with, and really is not a good match for it. I think results bear that out so far You can take that for whatever you want - I can only tell you why the system is there, historically and currently. That doesn't mean you have to like that idea, and you are welcome to rail against it. The question is not how then is one supposed to trust the law, because you already know the answer. The question is what one does about it. This is what HN has devolved into: someone taking adware and removing the ads is a "bad guy". Well, shouldn’t that be up to the original developer? He made a product and let people use it for free. But no-one is forced to use it. And there are other image editors without any ads. Some are proprietary, and some are FOSS, e.g. GIMP. What if writing proprietary and/or non-free software was the real evil?
LLMs have made everything open source. All software is free now. The Justice is the liberation of code from those that wish to seek rent from it. This is HN so nothing else to expect than Big Tech people giving us the scoop with the tagline "let's be realistic here". > In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice? Guess why trust in democracy itself is eroding everywhere and why even executing a health insurance CEO on broad daylight is not just widely approved but widely beloved. The rich can get away with anything (Trump's claim of "I could shoot someone on 5th ave and get away" is pretty realistic, to say nothing about the Epstein crap), but if you are poor or, even worse, an immigrant - pray to God to help you because not just will no one else help you, but in the worst case you might end up getting fucked over for seeking help. > executing a health insurance CEO on broad daylight is not just widely approved but widely beloved. An Axios poll showed 17% found the murder "acceptable" or "somewhat acceptable." Curious where you are seeing such wildly different numbers? https://www.axios.com/2024/12/17/united-healthcare-ceo-killi... Not a lawyer but I have friends get some results getting an LLM to send threatening lawyer type letters. Since you're here and on topic, a question that has been at the back of my mind because I feel that soon most software creators will be in this boat, with AI rapidly becoming able to clone software from observing behavior alone: Are patents the only real IP protection left for software? And would a patent (assuming this application had something patent-worthy to claim) help at all here? As in, in addition to sending a C&D maybe also including language about patent infringement would be more effective? I know that patents are unpopular for many here (including you, IIRC!) but I think this question is extremely important, especially to anyone who wants to make a living purely off the software alone. Remember: if no other moats or business models or funding models lend themselves naturally to the software in question, anything bolted on is pretty much already on the slippery slope to enshittification. A mechanism that encouraged people to compensate fairly for the value provided by software would be better for the Internet than what we've got going on today. The only effective protection for software IP is hiding the logic on servers you control (SaaS). Anything released to execute on client hardware can be decompiled and cloned. This has always been the case but LLMs have made the issue more obvious. there is no more software IP. ai does not need source: it can infer or deduce the logic or algos. and in the case of private software dont think it hasn't been sucked up too I've spent 0 seconds googling this so excuse the dumbfuck question but: is there any precedent or convention for writing off the stolen goods as losses? I'm pretty sure physical goods from businesses qualify but what about this?? Physical/digital has the same answer, just different effect. As a general rule, you can write off what it costs for you to make something, but not what you lose from not being able to sell it. Which means for physical goods, you write off the cost to make them, and for digital goods, you can similarly usually deduct development cost to make the software. In neither case can you write off the amount you would have made had it not been stolen/sale had not been lost. The practical effect is that because physical goods have a per-unit to-make cost, and most digital goods don't, physical goods get written off per-unit-lost and digital goods do not. At least, this is the most general answer I can give you for that level of general question. Could you just make a CICD process that for each minting of a software license it cost a person's time to review and accept and then the wages for that individual become the write off. I.E. Convolute the software delivery process so that like a physical good, it has a per-unit to license cost to recoup. Or would that be argued as it could have just been automated and it's not really a real loss leader just bad policy? You don't lose this time for pirated copies of your software, as I assume you aren't taking this person's time to create a license for pirates. To write something off you have to actually lose the money - writing off is a process to decrease your taxable income by your expenses, unless you're inventing fake expenses (read: performing tax fraud) it doesn't generate a greater amount of money than the expenses. Digital losses to piracy sounds like something that would be impossible to quantify.. even if they can prove that people are downloading these pirated copies, that's not proof that the downloader was ever going to pay for the software in the first place. You are the scourge of Earth and I hope you stop recommending how to "whack" developers. People like you are basically the mafia for Big Tech. I have been targeted by your industry for doing nothing wrong multiple times. Please don’t attack other HN members. It’s not nice and it’s against the guidelines. The poster recommended to "whack" developers and I merely pushed back on that. Please have better reading comprehension before playing police. First off, let me get this out of the way - I am not a lawyer. If you want a legal advice talk to a lawyer. Second, I am sorry this is happening to you. Third, based on GitHub's reply, specifically > we're unable to confirm a violation of 17 U.S. Code § 1201 they took your submission as 17 U.S. Code § 1201 takedown notice. Maybe you specifically stated this. Maybe it was implied. This is likely not what you want and GitHub's response is likely correct. The reason for this is that § 1201 prohibits circumventing a technological measure. The JS you host on your public site, even if obfuscated, very likely does not qualify for this protection. Another detail - the reason it took long (a month later according to your post) is that after the youtube-dl fiasco, they committed to manual review, legal and technical, of every 1201 takedown notice [0]. Fourth, if you believe these copies are sufficiently reproducing your copyrighted work,
what you likely want to do is file a standard copyright infringement 17 U.S Code § 512(c) takedown notice. This still goes through the same DMCA report flow but it should result in a less stringent review process and a faster response. Fifth and finally, consider asking your favorite LLM to get more context around these laws. Good luck! [0] https://github.blog/news-insights/policy-news-and-insights/s... Indeed, a 512(c) takedown notice is the way to do it. GitHub is extremely unlikely to ignore it. I run user generated content websites and would never ignore a notice. You definitely don't need to hire a lawyer to write it either. Just follow the notification guidelines in 17 U.S Code § 512(c)(3). This is bad advice. Obfuscated JS qualifies. 1201(a)(3): "As used in this subsection-- to 'circumvent a technological measure' means to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure, without the authority of the copyright owner" The problem is that AI can probably rewrite this JS de novo simply by observing its behavior and without de-obfuscating it. Or just ask first AI to create specs and another AI to do clean room implementation? Obfuscated JS can be re-hosted as is, and you can probably remove the ads with newly added JS code. Or just visit the real site and use an ad blocker? Re-hosting it would obviously be copyright infringement. Ad-blocking breaks the original site. A lot of functionality stops working properly. Sure, seems only fair that if you can try to block ads, the app can try to detect ad blockers. Circumventing a technological measure has been interpreted extremely broadly. Deobfuscation could be covered. > take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download Remember that there is still quite a bit of friction to doing that, and that many people have better things to do than jump through those hoops. In addition to the "hire a lawyer" comments in this thread, I suggest building in some heuristics that detect when Photopea is running outside of your domain. They don't need to be "foolproof," but add additional friction to pirating Photopea so that less people will jump through the hoops. Some historical examples: - Commercial software in the 1980s and 1990s would burn a hole on the disk, and the software would look for the error when reading that sector. - Donkey Kong Country would detect that it was pirated by reading the amount of RAM available. (Because SNES backup systems had slightly different runtime properties than the real cartridge.) More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt. --- Finally, you could consider a business model that relies on server-side functionality for revenue or stickiness, that's hard to replicate merely by pirating the software. (IE, some kind of server-side storage and sharing system.) > Remember that there is still quite a bit of friction to doing that If they're using the github.io repo, the web app can be just as accessible as any other site Techniques like what you describe made a little more sense when the means to even figure them out were less feasible for the average person, especially before the web had much information on reverse engineering, when powerful debugging tools weren't as accessible or free. Today, there is little point in trying to slow down software pirates. At best, adding an arbitrary piracy detection only adds anywhere between mere minutes and a few days to the effort to crack software. This is true absent AI assistance or even a meaningful understanding of ASM outside of logical JMP instructions. The author will likely waste more of their time implementing anti-piracy techniques than a software pirate would figuring out which function call results in the program exiting abruptly. I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities. This is in spite of various licensing and contextual checks throughout. It would slow down a pirate more to have a program modify or decompress itself in memory, but that class of techniques is still more trouble than it's worth. Experienced pirates already know how to deal with those traps. The timeout thing you mentioned is clever, but the type of person who knows enough to disassemble software would think to themselves "wtf does it crash after 5 minutes?", immediately investigate, and identify the source of the crash. Having a license check is the only thing authors of software should bother with. It provides most people a framework to consider whether they should pay for a product. Most people won't download potential malware from a sketchy website if you offer your product at a fair price. Those who either know how to crack apps or refuse to pay will keep doing what they're doing. tl;dr Don't fool yourselves into thinking you'll outsmart a kid with Ghidra installed by throwing a glorified if-statement in their path. EDIT: I'm speaking in the general sense. The same principles apply to an app that runs almost all of its logic in the browser. > I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities There are some, with code consistency cross-checks and such. Cracking them with static code patching can get very time-consuming. Patching them dynamically works, but some have checks for that too. It's not common though for sure. Yeah, I'm sure they're out there, but it's very rare in my experience. I'm a micro-brain when it comes to cracking software, and I've almost never encountered this, whether it's small fry software or something from Microsoft or Autodesk. There was some software with debugger detection I came across once (can't remember which it was), but that's the kind of thing where lots of existing workarounds often exist by other crack-ers. I'd recommend taking a look at DRM for games. It's been a while since I read anything, but AFAIK Denuvo is still effective enough to protect newly released games for weeks. I've spent some years in gamedev and doing PC versions was a big part of it. I have seen countless attempts at 'code consistency cross-checks' and they all have been defeated. The only thing that came close was Denuvo. You may want to read up on it before dismissing it. It's sad that folks here will downvote and hate anything about it. What it changed is that publishers got their money from people playing on PC and some of it was spent on developers to actually improve future games =) > More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt. This is a very frequently repeated point, which is invalid. Crashing pirated versions do not affect the reputation of the original. It’s an urban legend. People using pirated versions are perfectly aware of the fact that they are using butchered versions of the original. So when it crashes, chances are it's because of a botched DRM bypass. It's an obvious connection, has always been. Is there a ticket code or other contact you've been in touch with? As for DMCA filings, we publish all of them here: https://github.com/github/dmca I see two from Photopea, one from 2022 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) and one from 2024 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) - could you point to the recent filing? I work at GH, but am not involved in DMCA filings, and can in no way answer or judge this case, but potentially follow up internally. Thanks! One is Ticket 4822535, another is Ticket 4726557. Github did take down this https://github.com/spooknik/Photopea-Appimage and other repos in the past, but now, I feel like I talk to a robot. I am happy to hear that they have real employee! :D Hey guys, thank you all very much for your comments! I just woke up, I did not really believe my post would get this much attention, so thanks! Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it. I think I will try solving it with a lawyer. But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff. A lawyer will probably get you damages for the infringement and is less hassle than trying the whole process yourself. I could find are a bunch of Photopea repositories on GitHub, but the authors are all either from China or Russia, so getting damages for infringement will be difficult to enforce. Hiring a lawyer sounds like a waste of money to me. You might be able to get damages from github, especially as they have ignored a notification that there was infringing material. A lawyer would know. The US allows damages per infringement without need to prove an actual loss, and per infringement. We don’t know if OP filed the DMCA “optimally”. In my experience GH usually does 512(c) takedowns in days; so it taking a month is quite abnormal. OP’s posted response suggests he didn’t file a copyright takedown but rather an anti-circumvention claim; which is a bit special in DMCA law, and generally best avoided when you have merits to do a regular 512(c). We also don’t have details of the repo. The author has commented on another project that claims to be a LLM _re-implementation_ of Photopea, without directly using source. If that’s the case, it’s entirely understandable why GitHub won’t take it down. Github supposedly manually verifies 1201 claims, which would explain the long wait on the response. Sadly though, you have to do the cost/benefit analysis of the legal process and your likelihood of recovering anything. I spent $18k in legal fees over a $22k claim in a construction dispute. I won the suit and was awarded legal fees. So I'm owed $40k plus interest. I've collected exactly $0. The last lawyer I spoke to said I need to cut my losses in legal fees at some point because from a practical standpoint, winning damages isn't the same as collecting them. Especially if the defendant isn't local and has few assets. I've used Photopea for small editing before, and even though it's not my daily driver, it's a really cool project. > But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff. I think anybody in any line of work or life would like that. It's however unlikely to never run into an issue where a lawyer is really needed, so don't hesitate when you realize you need one. Someone recently posted a link to Mike Monteiro's "Fuck You Pay Me" talk. It's one for the ages: >Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it. It worked for me! And very quickly. https://news.ycombinator.com/item?id=49832406 But it is a bit crap that this is the only way you can get Github to behave responsibly. Good luck. [flagged] How dare a developer expect revenue for his work, especially from users who we all know are, in fact, entitled to get everything for free. > users who we all know are, in fact, entitled to get everything for free That kind of thing is explicitly required under HN rules - if a company requires payment, it's only OK to post if a “workaround” to avoid paying is available. Additionally, HN explicitly say it's OK: * For HN comments to ask how to get around payment requirements, and * For HN users to help other users to get around payment requirements Source: Official HN FAQ page Why should HN be allowed to have rules on what content is allowed to be posted? People are of course free to not post. If he wants revenue he can restrict his product to paying users. Double dipping with the popularty of free access only to abuse users with spychological manipulation spam should never be accepted. Depending on your definition, shareware models have been around for 40 years at this point. If you disagree with the terms, don't use it. That's a personal decision though, not a global moral position. If you want to use it despite the ads, use it. If you don't, don't. It's that simple. Be an adult, make a choice and live with it. That's not how the world works. Spamware kills honest alternatives so you won't have a choice. How does it kill them? ETA: I dispute the implication that "honest" software is a category that necessarily excludes all ad-supported software, but that's a side story. Thank you for saying this. It's literally insane to me how thoroughly entrenched this sense of entitlement has become. It's at the point where it can't even be parodied, because a chunk of society, maybe even the majority, seriously holds the view that they are entitled to any software thing they want for free. I once posted a joke about how I love leaving shopping carts everywhere so that cart pushers have a job, and got enthusiastic replies supporting me. You should discuss this with an attorney that is experienced with IP law to see what your options really are. IP law is very complex and sometimes very surprising. You need expert legal advice, not advice from the HN crowd. As an aside, I thought that "cracked" software meant software that has had the copy protection or other access control bypassed or removed, not the alteration of the software functionality itself. If your software was actually cracked then you may have some fairly heavy law in your favor. For better or worse, bypassing access controls (even weak or simple access controls) gets special legal attention. What is the cost for doing this, out of curiosity? If OP only earns a trickle of revenue from their site, it probably isn’t even worth the money (?) Most state bar associations have a free consultation line that will refer you to a reputable lawyer to start with and do basic consultation on where your issue should go and how much it will be. If I had to guess, getting advice is probably $100 and having a lawyer send a letter is $250-500. IP lawyers tend to be at the more expensive end, typical billing rate in US of $500/hr last I looked. But yes, being able to do a letter quickly is probable. A lot of lawyers will give a free consultation, and in my experience (not for IP) they will give decent expert advice for free. No harm calling them. He earns 7 figs a month from it iirc, was featured many times on HN as a successful indie hacker. >He earns 7 figs a month from it iirc, Less than 7 figures (~1 million) per year -- not per month -- based on previous comment from 2021: https://news.ycombinator.com/item?id=26769141 A later 2023 interview updated it to ~$200k/month (~2.4 million/year) : https://web.archive.org/web/20240606073354/https://saastrapp... Still enough to hire a lawyer and at least do a few consultation sessions. That's a necessary business expense. (I'd just quit my job if I had an income like this.) That comment was over 5 years ago. That's a long time, and from estimates he has millions of users now. Definitely making big money. If that’s true, he doesn’t need free legal advice from us. True, but then again, the post is titled “Tell HN”, not “Ask HN”. Maybe it’s just a case of the poster trying to raise awareness. ... they're just trying to get the attention of someone at GH that can do anything OR create bad press that they then have to deal with. But pressuring them on HN to act about their sub-par anything is.. arduous, given their.. tolerance. Man, some of the comments this is getting are absolutely wild. OP, I’m sorry this is happening to you. It must be incredibly frustrating to have people ripping off something you’ve worked on for many years and pass it off as their own work. I would be furious in your position. I wish I could do something directly to help you but the best I can offer is to echo the best advice others have already given you: it’s time to get a lawyer. That is the one guaranteed route to get GitHub to sit up and take the action they should already have taken on your behalf. The 3rd U.S. Circuit Court of Appeals recently ruled [1] that using AI to train on a competitor's copyrighted material to build a competing product is _not_ fair use. This is a recent ruling (September 30, 2026). GitHub policy has surely not caught up yet and who knows when it will. > Do you think I should look for a lawyer to deal with it outside the digital world? Absolutely. This is a copyright infringement case and there is now an appellate precedent to cite. Gather as much evidence as you can and speak with an IP attorney. [1] https://www.reuters.com/legal/litigation/unsealed-opinion-sh... You're right that this is a copyright infringement case, but I'm not sure if AI is relevant here, as it seems like a pretty straightforward rip-off. Also TFA is about a much narrower ruling than it first seems: >The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content — and the appeals court said in a footnote that concerns raised by the US Department of Justice in a copyright lawsuit against OpenAI "do not apply here." How is this enforceable with llms if they train on generalist material, which is already the case? I don't think it's enforceable or even applicable here. "The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content " this comment is misleading. ... and we all know our idiotic/corrupt Supreme Court can and likely will overrules that very sensible ruling with something crazy ... ... so virtually no one considers that ruling to be the final word on the topic (sadly). You’ve made a million dollars a year for five years with it? Why are you stressing about lawyers and support tickets instead of being retired? This is a really weird take. OP worked on this during all of their free time for over 10 years. And it finally took off into making a solid revenue for them. This is a rare success story for an indie developer. We should be supporting them. It would suck for anyone to get their life's work stolen and given away for free, which is what is happening here. -Another indie developer who hopes to have 1/100th the success that Photopea has had. There can never be enough money for these people. C'mon. Poster has a valid concern here. We do not want places like github drag their feet for a month over such concerns...at least I don't. I think we're going to see a lot more of this going forward. I think we're also going to see the strategy to be to remove the processing and magic sauce from the client and move it to the server where it can't be decompiled and rebuilt with AI. Apps like photopea exist because of client side processing. They shift cost to client compute and that makes them supportable by indie devs. I'd wager we will start to see more web apps like this have greater obfuscation and dependencies on operating on a particular domain. Sure AI can help to circumvent many things, but at a certain point they pay-off may not be worth the effort. You think AI can't recreate it based on the outputs? 1:1? No, because AI won't know all the outputs, only the ones you show it. Also if it could recreate it that would be fine, because it would be doing so without having access to the source. > because it would be doing so without having access to the source I find it unlikely that photopea was never scraped for AI training considering they are looking so hard for new material they started buying up and scanning old books. When it can do that, the people can also describe the output, i.e. the fact that your original website even exists is irrelevant for what people are able to do. Since these clones already exist, it means that even if Photopea moves to server based (which it should have been in the first place), the code is around and will work forever. The magic sauce haven't been in the client for many applications for years. Google barely has any application that runs on desktop OS even though they could have released them. >, it means that even if Photopea moves to server based (which it should have been in the first place), It's a 1-man operation so it may have not have been financially viable to architect the app as server-based. - server-based : must invest a lot more money in server farms and extra disk storage, or pay high AWS cloud fees. E.g. if a million users do a blur or denoise filter, all that cpu processing has to happen on the servers, and massive disk space to hold the intermediate files, and extra bandwidth costs to send the changed bytes back to the client. - client-based : just ship Javascript blobs to end users' web browsers because the blur/denoise/etc filters happen on the desktop. Also, this type of pixel-editing software still needs a ton of client-side Javascript to behave like a Photoshop clone because users want to see interactive changes as they dynamically slide the blur/noise/etc settings. Round-tripping that with extra server latency is not a fluid UI experience. We can't confidently replay the past and say that starting it as server-side app from the very beginning means he'd have the same $million in revenue today. Instead, the extra server costs and UI jankiness could have doomed the project. I understand all of that. It's a business decision, and I'm not sure if they made the right decision. Most client-only web applications are open source because they know there is no business in selling it as a service. Photopea somehow is an exception, but its business model is getting questionable which is not a surprise at all. It's also possible to use a combination of cloud based and local computation. Figma is doing quite well in that regard, especially with the use of WebAssembly. No doubt that potentially means more work, and potentially forcing users to create account etc. But hey, that's a business decision as well. If you don't do anything but just keep everything in JavaScript, this was going to happen. > server based (which it should have been in the first place) Server-based photoshop clone sounds more like VNC/RDP, for this sort of thing client processing is a better UX. This ship has already sailed, and most people in tech circles didn't even notice. SaaS killed Open Source with it, two decades ago. With all due respect: people should be able to do this. Copyright as a concept applied to code was always a god-awful idea, DMCA especially. And for JS served on the open web it's plainly comedic. Someone can always make a new repo without redistributing your code, sourcing and hot-patching it directly from your domain. GitHub deleting this repo won't ever fix it, you're playing whack-a-mole and doing free PR for these repos here on HN. We seem to forget that this website is called Hacker News. > Copyright as a concept applied to code was always a god-awful idea, DMCA especially. And for JS served on the open web it's plainly comedic. Why is it comedic? All of my own code is open source and freely available, but protected by copyright -- namely via the GPL. Copyright is what helps ensure that we retain open code, and ensures that it propagates openly. How much further along the enshitification path do you think Android would be, if Google wasn't bound by the GPL in so many areas? Copyright with code is not only fair (why on earth would creating code be different to creating anything else?) but it is what keeps so many things free and open. I think GPL was though of and is an answer to the idea of copyrighting code. If there was no copyright for code, there might not be any copyleft license. If we were all allowed to freely copy and modify and redistribute etc., then there would be no need for licenses enshrining these rights. Hard question to answer. If there were another phone operating system, built on a combination of permissive and proprietary software, from a company which notoriously avoids 3.0GPL like the plague, and minimizes use of 2.0GPL whenever possible, then we'd have a fair basis of comparison. Guess we'll never know. > Copyright as a concept applied to code was always an awful idea That may well be, but as long as that concept exists in law, I sure would like every developer to be able to benefit from it equally, not just Microsoft and Adobe. I disagree. I think someone can take this code and write their own based on it. Not use his verbatim. At the end of the day the fact many people abuse IP laws doesn't mean there are no legitimate uses. I would like to think more deeply than this response. I do not want enshittified software that creates a bogus need for a server in order to extract licensing fees from me. I prefer to pay for locally run software, paying in ad views if I have to because that’s the micropayment system we have ended up with. So is there a path to an ethical, viable business model for the author? I don’t want people telling me I can’t modify code sent to my machine to execute. Stopping me from editing out parts I don’t want to run seems odd. If you want me to run certain things, do it on your own hardware. This reminds me of the arguments against ad blockers. I don’t want people to force me to watch ads and not allow me to block them on my own machine. > So is there a path to an ethical, viable business model for the author? Yes and no. An ethical business model for software in this world must be built on a long process of collecting good faith from customers, it just doesn't pay well enough compared to the ones that shatter said faith (adware, exploitation, dark patterns). I think the software moat will be more and more based on social capital. People are happy to pay for the software if they know for a fact that company/person behind it isn't being hostile to them. Look at Steam as an example of this. And you can always open source your code, and still make money through the means of good faith. Is it actually viable? I don't know. It depends on how much money you want to make. Sure. One example of a path, that many people are already doing, is a system like Patreon. The old model of server-locked licensed software is going the way of the dodo pretty fast right now, though people may not realize it if they're not hunting for alternatives to the old guard suites yet. And while personally I agree with the commenter above you for personal reasons, I also think that the OP is missing that while the people who've ripped their js tool may have done so directly from their site, no one certainly has to any more: they can likely black-box something similar pretty quickly, at which point the author's DMCA moat is gone. Charge upfront for development (patrons, sponsors, etc) /and charge for support and training resources. Open Source the code. That is my preffered business mkdel for software development. I don't believe that "ethical" and "ad supported" are compatible. Harvesting our private data and selling it to the tech-dystopia to further curate profiles about our every move can never be considered "ethical", imo. From my perspective, those people who are taking this public client side code (not emulating any kind of server), and removing the privacy nightmare, are actually doing good for society. The software is more usable, more performant, and far more secure when they are done. The only harm is the authors ability to monetize. I don't think it's possible to have a fully client-side web product and be able to enforce strict guardrails on the use of the code. Regardless of ethics, it's just not feasible. What you give up by delivering the full source code to the browser to render is control over the source code. If the author wants more control over their source code, and easier monetization, they should compile a binary and distribute that. The guardrails protecting source code, duplication, and copyright infringement are much more clear. That's just the harsh reality of delivering source code to clients. In an era of slop, quality is king. I honestly think the author should just ignore the cheap clones and continue selling quality software. The idea that the clones are perfect, bug free, or will continue to be maintained and hosted is a fantasy. There will always be people with low incomes in the third world trying very hard to get something for nothing/cheap, and they are the worst customers. No loyalty, highly intelligent, and will drop you immediately if a competing offer is 1% cheaper or offers what they need for free. Adverts are likely a poor business model here - if you want to sell to professionals and creatives, the visual look of the software matters. It should really be subscription or one time licence > is there a path to an ethical, viable business model for the author? .. is something the author should have considered before deciding to publish AdWare. It's inevitable if your entire product is statically hosted and pulled into their browser. They didn't even need AI to do this, they could have just done it by hand anyway. Regardless of what you do now, I think you should be prepared for the upcoming reality that LLMs are going to be able to reproduce software, feature-perfect, in a way that does not currently violate copyright law. Right now, the settled law is that such an LLM reproduction is 100% legal. If you really want to protect your software in the years to come, you might have to seriously consider starting some sort of popular political movement to address this issue in copyright law. Current models can already do a full reproduction of anything with source code available (e.g. JavaScript...), and there's already been some poor-quality Photoshop knockoffs. I feel like I need to nitpick a little:
Models don't need source code available to reproduce software. See all the "full decompilation" projects cropping up. There's no putting this genie back in the box, because LLMs can also "refurbish" a project enough that it ceases to look like the original. People don't bother now because they don't have to, but in a world where they'd get hit with copyright notices, they would. > Right now, the settled law is that such an LLM reproduction is 100% legal. How so? Interfaces are not copyrightable, but that it not the same as dissecting a js bundle and copying the implementations. Are we sure these LLM are keeping sanitary habits there? if you've used any Ai in your own code authoring, copyrights may be completely out the window several courts have ruled Ai output is not copyrightable, I am unaware of any co-authored cases If you only used the output of an LLM, then you don’t qualify. But, the use of LLMs is not disqualifying. To qualify for copyright protection your work simply must have a sufficient degree of human authorship. However this is just about protection, not infringement. If you use an LLM to generate something and that LLM just happens to output something that another human wrote, you may be liable for copyright infringement. Are you a lawyer? Here's an article from Jones Day that confirms what I just said: https://www.jonesday.com/en/insights/2025/02/copyrightabilit... That doesn't top people producing copies though, just trying to copyright the copies. it also means that you cannot claim copyright against copiers, the context here being the original has had Ai involvement in the development process > Right now, the settled law is that such an LLM reproduction is 100% legal. Where did you hear that? Because it is 100% untrue and is the opposite of current legal guidance from reputable legal expert > popular political movement to address this issue in copyright law. Or perhaps the people should admit that copyright, an artificial construct which is not rooted in natural property, was inherently broken and is not (or at least no longer is) a net benefit to the society and simply adapt around it. Only if I as a human being get the same rights to e.g. Microsofts code as they get to mine via legal trickery in your world. You do. Just point the LLM towards windows.exe and tell it to party on. Won't work this year, but it probably will next year. Copyright is done. I was watching a video talking about how a world before copyright allowed innovation to spread quickly and allowed people miles away to iterate faster. Even if LLMs reproducing feature perfect software is deemed a copyright violation, people will just do it privately and use the software themselves. I’m personally waiting for LLMs to get so good that I can make music and movies based on my favorite ones. I probably could never release it to the public, but being able to make it and enjoy it myself would be amazing. Another thing that can help contextualize this phenomenon is mix tapes, which are fair use in the US. Modifying/modding/remixing software was simply not as feasible as music, but LLMs made it possible. There is something similar happening in the game modding communities. One of my favorite streamers had claude write a little mod to change the UI of KSP so it kept with the larger fanciful theme of the game, over being so sci-fi-ish. He didn't like, he changed it, he's probably not going to release it because of sensitivity in the broader gaming ecosystem. I have agents maintaining several patches to my main tools, not forking, not sharing (some have no interest), personal adjustments > he's probably not going to release it because of sensitivity in the broader gaming ecosystem There is basically zero pushback to generated code. All the crazy Minecraft in GTA type mods that came out in the last couple weeks are obviously vibe coded but no one cares because they play good and surprisingly bug free. If he put in AI visuals as in generated textures then it's different, because that's way more visible and gets labeled as slop immediately. There's also the (accurate imo) perception that AI is taking artists jobs against their will but coders adopted it on their own and benefit from it, so using it for code is ethical from a labor rights POV. I believe it is a lot closer to CSS, some images for buttons that needed inverting, closer to dark mode That world worked because the ones doing the research were either self-sufficient hermits (often self-sufficient by necessity as they were outcast for "being mad"), financed by the Church or financed by a rich person (usually the fiefdom's ruler, sometimes independent wealth). Copyright, patents and IP are the evolution of our (Western) way of converting research into a form of financial investment. Patronage and support of the arts (and sciences) was a great value proposition for Churchmen in old times. You could commission works of music or sculpture or stained glass or what have you, and these were of course well-fitted to be installed or performed in the confines of your church and serve the liturgy. So they were collective goods that were enjoyed by many; they attracted locals and they beautified their surroundings, and they encouraged pilgrimages and stimulated income if you could become particularly distinguished and attractive, based on the beauty lent by your artisans and artists. And a big church could employ lots of them, and thereby stimulate the economy. It seems that the Baroque Era and churches crammed to the rafters with art, may be an artifact of a very good job market for those architects, craftsmen and artists! Yeah... you could copy some sheet music and share it around, but it still required skilled musicians to perform, play and sing it. And nobody was taking photos or uploading JPEGs of your art and sculpture, so it was fairly locked-in that people needed to visit, and see it in context. So it stood to reason that you could probably reconstruct Noah's Ark from the fragments of True Cross that were circulating around Europe... and how many fingers did your favorite saint really have? Copyright-free church economics have sort of fallen apart since then. However, museums, arena concerts, theaters and the rest, they have all taken pages from the Church playbooks. The fact that a church can still draw in hundreds for a show with great production values, every week or daily, seems dull and unremarkable now, but a good rock concert or museum collection can evoke the same "goin' to church" fervor in people who like that kind of stuff. Can you post the actual link of the repo? You'd get responses with more context. You had commented on the photocraft post prior, so if it's that, then it's a bit muddled. It's a LLM based re-implementation and not a copy of the code made open. So the argument would be weaker there, and you'd really need specific code samples to make a case of copyright infringement. Photocraft not "piracy" as is normally understood, which is the exact same binary, optionally with the license protection removed. It sounds like you might have a case for copyright infringement. Resolving the situation yourself has failed. Your next step is to talk to a lawyer. Nowadays useful software either resists being copied/distilled or it will be with minimal human effort. Look at Adobe Photoshop was just ripped as a clean, open sourced project: I use photopea for years and really respect what you did. I disabled the adblocker. I hope they remove that. Yeah I’m a huge fan too and pay for a subscription. It has basically fully replaced Photoshop for me for at least a few years now. Between Inkscape and Photopea I haven’t touched an Adobe graphics app in years. T.I.L. about photopea, and I have disabled Ublock Origin for the site. I see a static 'slide show' column of non-video adverts on the right hand side of the screen - about 10% of screen width. Best of luck with the copyright complaint. > Thank you for submitting a DMCA takedown notice. We've reviewed the information you've provided, and based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201. Did they actually republish you code or were they just creating wrappers that download/cache the code from your website to run locally? Sorry this happened to you dude. I don’t want to be harsh but, out of the crimes ignored in this era of AI clean rooming, book destroying distilleries and a despondent ostrich adjacent legal system you do seem to be one amongst a deluge of cheated individuals. Hope you manage to get it sorted but I have no idea how that would go down at this point. I’m sure at least one of them could claim they copied it off the other ones and then you’re shit out of luck. Yes you need a lawyer. You may not have filed the DMCA request correctly. You may not be understanding the law correctly. <Naive> Run the code you want to protect in a cloud function.
Cache the user data on the server; modify it on the server,
send the diffs to the browser. </Naive> <MoreNaive> Any product that agent can generate from a prompt or reverse engineer will be cloned. </MoreNaive> <MostNaive> Solve problems that make your life better even if cloned. </MostNaive> I think what you want is a legal avenue, like Trademark, Design rights, or patent. If you have one of these, it’s possible that GitHub would honour it if you go via a lawyer. I am in the same situation where people are hosting copies of the software for commercial use in companies. Even as big as Tencent. That is not allowed with my license and they also went to remove the code that does the license check on application startup. GitHub’s response so far: “please give an explanation how they can become conformant so that the users can fix this.” A talk with a lawyer would be advised. But this is money you may not want to invest.
You could just go on, keep your product improving and proof this way that your solution is more worth than the copycats out there.
You just realized how it is to be a valuable target. I'd recommend to DM github's VP of dev relations: https://github.com/martinwoodward before starting heavy artillery with lawyers. (Martin also often posts on HN). > What do you think I could do? Hire a copyright lawyer. Start going after the people that run this as a service, for both copyright and trademark infringement (you have a trademark for photopea right?). question: the code on Github is an issue (plenty of answers on that), yes, but is people hosting copies of your service a bigger issue?
In other words, they are probably similar people that do it without publishing on Github... just move crucial bits in another language and use webassembly. so good section of your code is in compiled binaries hence blocking anyone stealing your IP. also at the moment they just change some bits I don't think it'll be long before they can just recreate a new project with different code but with exactly the same functionality and then you got no protection afaik(although not a lawyer so not 100% sure). > just move crucial bits in another language and use webassembly. so good section of your code is in compiled binaries hence blocking anyone stealing your IP. Can't you just steal the entire WASM code just as easily? I mean, I guess if the ads are stuffed in WASM that becomes a problem. But LLMs are pretty good at reverse engineering. I can't imagine it would be too much effort to get them to take the ads out, or to replace your ads with their ads. LLMs can decompile assembly code quite well these days, so I doubt that WebAssembly will be a hurdle. I was like oh cool... until you mentioned the ads. I would not fork or re-release proprietary code. I would ask my LLM to write a very rigorous end to end test suite for your tool, delete all the code, then have a clean context LLM re-write the code to pass all the same tests. Then I could publish it under an open license. Ads are a cancer, and it is a matter of weeks before someone does the above where you have zero recourse. I suggest open sourcing the code properly without ads yourself before someone does it for you. If you do that someone might donate to you instead of paying for the tokens to clone your work. Software is no longer a moat and DMCA means nothing anymore. True. I understand the author on the emotional level, but the fact that a lot of work went into the product does not mean that it is that valuable. The author should focus on making the product better - unfortunately (for them) that means inventing a new business model. Someone speaking the truth. A closed source, client-only "desktop" application, especially a web app with obfuscated/minimized JavaScript code, has no real copyright protection these days. You either sell ads, sell it to enterprises, or if you are lucky enough to be able to pull it off, sell a subscription. Not putting the logic on the server in the first place means everything is basically public knowledge. How are you supposed to make a living without ads in this "ecosystem" or should we say walled garden? Supposedly like any software company selling their product or a service. If ad was the only way to get money, there would be no product/service to sell anymore and thus...nothing to advertise. It just cannot work that way. I was a software engineer and pivoted to full time security about 10 years ago. Security will be in demand for a while longer I selfishly suspect. As a reminder, this is the year 2026. Photopea is lucky that it has a decent amount of revenue. But that's an exception, not the norm. Generally speaking, for new software, the business model of desktop, client-only software hasn't worked well since late 2010s at least, and nobody should expect to run a viable business like that today. There are very few applications you "install" on your computer that doesn't require native capabilities in some way. Adobe buys ads rather than sells them, is that correct? How are they making money? You aren't. People aren't going to be able to make a living in software anymore, unless they work for a corporation. And even then, that's disappearing as well. When the whole industry manually punched machine code into punch cards, people were threatened by assemblers taking their jobs, and then later by compilers, and now by inference engines. The real engineering work that will always be paid for is identifying problems and testing solutions to see what solves the problems. The substrate in which we use to do that will change, but the job will endure. Those that just do what they are told however, yeah they are SOL unfortunately. Creative problem solving is the only skill that will matter anymore. And how many companies need creative problem solving? Way less and less. The problem is the moat is getting higher. Name any other profession that is kneecapped worse than by the free open source movement and the like. Meaning you can't monetize what you create. Or the usual ways are non-conformant, dictated by the corps and their mindless followers. Almost anyone learn anything they want now. This all cuts both ways. If security is a solved problem then anyone that wants to teach themselves enough can move to trying to solve disease, until disease is solved, then we all move on to building enough robots to mass produce enough food to solve world hunger and shelter... and once the needs of everyone on earth are solved at an ever cheaper price until it is free... then I guess we do whatever we want. Only way to earn a good living is to pivot to solving diseases for a few years until robots solve world hunger and shelter. Then we can do what we want without the money to do it? I want a post scarcity society where money has no meaning. Capitalism is just a bootloader to get us there. There will always be scarcity, it is unsolvable problem. Humans needs can't be met, people will always want more.
DannyBee - 7 hours ago
voakbasda - 5 hours ago
DannyBee - 4 hours ago
cassonmars - 5 hours ago
bsoqk - 2 hours ago
cpach - an hour ago
45sdasf45 - 4 hours ago
keybored - 5 hours ago
mschuster91 - 3 hours ago
initatus - 3 minutes ago
tim333 - 4 hours ago
keeda - 3 hours ago
nradov - 3 hours ago
modzu - an hour ago
monster_truck - 6 hours ago
DannyBee - 5 hours ago
plumbees - 5 hours ago
thenewnewguy - 5 hours ago
ktm5j - 6 hours ago
kittikitti - an hour ago
cpach - an hour ago
kittikitti - 34 minutes ago
thought-gap - 16 hours ago
tothrowaway - 6 hours ago
eli - 6 hours ago
keeda - 3 hours ago
cute_boi - 3 hours ago
darkwater - 5 hours ago
eli - 5 hours ago
Maxatar - 2 hours ago
eli - 3 minutes ago
apefulsin - 7 hours ago
gwbas1c - 7 hours ago
svantana - 7 hours ago
ravenstine - 5 hours ago
eps - 4 hours ago
ravenstine - an hour ago
Timon3 - an hour ago
SleepyMyroslav - an hour ago
abcd_f - 6 hours ago
summarity - 11 hours ago
IvanK_net - 11 hours ago
IvanK_net - 14 hours ago
graemep - 8 hours ago
gpugreg - 7 hours ago
graemep - 6 hours ago
dannyw - 5 hours ago
zdragnar - 5 hours ago
kevin42 - 5 hours ago
Qwuke - 10 hours ago
brnt - 14 hours ago
ChrisMarshallNY - 9 hours ago
hermitcrab - 7 hours ago
Kivan_net - 13 hours ago
flanked-evergl - 13 hours ago
no-name-here - 10 hours ago
asdfaoeu - 9 hours ago
account42 - 13 hours ago
tweetle_beetle - 12 hours ago
akoboldfrying - 12 hours ago
account42 - 12 hours ago
akoboldfrying - 12 hours ago
akoboldfrying - 12 hours ago
apt-apt-apt-apt - 10 hours ago
JohnFen - a day ago
y-curious - 16 hours ago
Shank - 15 hours ago
Scaled - 10 hours ago
janalsncm - 15 hours ago
Onavo - 15 hours ago
jasode - 11 hours ago
fg137 - 9 hours ago
schnebbau - 9 hours ago
janalsncm - 15 hours ago
msdz - 14 hours ago
pluc - 10 hours ago
bartread - 20 hours ago
hgs3 - 5 hours ago
keeda - 3 hours ago
alightsoul - 4 hours ago
hungryhobbit - 4 hours ago
jodrellblank - 6 hours ago
thraway3837 - 3 hours ago
fishgoesblub - 6 hours ago
TheSkyHasEyes - 6 hours ago
schnebbau - 11 hours ago
anakaine - 10 hours ago
lesspassiveobse - 11 hours ago
schnebbau - 11 hours ago
alpaca128 - 8 hours ago
1718627440 - 11 hours ago
fg137 - 9 hours ago
jasode - 8 hours ago
fg137 - 7 hours ago
flomo - an hour ago
TeMPOraL - 11 hours ago
lewelove - 8 hours ago
epihelix - 5 hours ago
zelphirkalt - 15 minutes ago
samatman - 2 hours ago
p-e-w - 8 hours ago
Roark66 - 7 hours ago
fn-mote - 8 hours ago
prepend - 8 hours ago
lewelove - 8 hours ago
ang_cire - 8 hours ago
limagnolia - 7 hours ago
criley2 - 8 hours ago
RugnirViking - 8 hours ago
gewetensleegte - 8 hours ago
MisterMunchkin - 9 hours ago
handoflixue - 20 hours ago
nathanlied - 20 hours ago
14u2c - 20 hours ago
verdverm - 20 hours ago
kube-system - 15 hours ago
fg137 - 9 hours ago
kube-system - 5 hours ago
abrookewood - 20 hours ago
verdverm - 20 hours ago
kube-system - 15 hours ago
tgma - 20 hours ago
account42 - 13 hours ago
CamperBob2 - 4 hours ago
theturtletalks - 20 hours ago
tgma - 20 hours ago
verdverm - 20 hours ago
tancop - 13 hours ago
verdverm - 7 hours ago
mschuster91 - 13 hours ago
ButlerianJihad - 13 hours ago
anilgulecha - 16 hours ago
jdlshore - 21 hours ago
hereme888 - 5 hours ago
msalihb - 11 hours ago
sen - 11 hours ago
2b3a51 - 10 hours ago
jameshilliard - 20 hours ago
B4uler5 - a day ago
binlog - 21 hours ago
swframe2 - 5 hours ago
aetherspawn - a day ago
BSVogler - 14 hours ago
SeriousM - 12 hours ago
jakub_g - 12 hours ago
throwawayffffas - 11 hours ago
maximegarcia - 4 hours ago
pdutt111 - 7 hours ago
onlyrealcuzzo - 7 hours ago
gpugreg - 7 hours ago
lrvick - 21 hours ago
klntsky - 15 hours ago
fg137 - 9 hours ago
lofaszvanitt - 20 hours ago
prmoustache - 10 hours ago
lrvick - 20 hours ago
fg137 - 9 hours ago
verdverm - 20 hours ago
Madmallard - 20 hours ago
lrvick - 20 hours ago
lofaszvanitt - 20 hours ago
lrvick - 20 hours ago
ipaddr - 14 hours ago
lrvick - 11 hours ago
MentalM - 5 hours ago