Sorry this happened to you dude. I don’t want to be harsh but, out of the crimes ignored in this era of AI clean rooming, book destroying distilleries and a despondent ostrich adjacent legal system you do seem to be one amongst a deluge of cheated individuals.
Hope you manage to get it sorted but I have no idea how that would go down at this point. I’m sure at least one of them could claim they copied it off the other ones and then you’re shit out of luck.
I personally know Ivan. For many years of his life, every day, he programmed algorithm after algorithm in this complex online photo editing tool. Essentially, he devoted half his life to it. And now, when someone has literally stolen his work, nobody is reacting. And that's terrible. I think it's absolutely terrible. GitHub should respond to this.
I've seen people on Reddit writing things like, "Come on, what's the big deal? AI can write any code now." I disagree. There are hundreds of thousands of lines of code here, very complex code, which even AI wouldn't be able to write on the first try or in a single day. So this person stole this code from Photopea and built a product on top of it.
Yeah, this bodes well for my meditation app frontend I'm going to release on GitHub. It should be fair use ish but it does seem GitHub is fairly friendly anyway.
Headspace without being tracked and having data brokers cross reference "anonymized" (sic! word wasn't in keyb. dict) info on when I meditate, using which program etc.?
Headspace updated it's privacy policy info recently, which got me to have it checked with an LLM. And it turns out that what you're doing on $100 per year meditation app is still being sold to anyone willing to pay. Using headspace lost it's charm. I wonder if Andy ever agreed to this.
I saw someone who claims to have re-implemented Photoshop in Rust using clean room specs. I haven't checked into it yet, but it seems to have a lot of interest.
Thats what the copyright lobby wants you to think, but honestly, if i copy your digital item, im not stealing it as the original still exists in your possession. That you might infringe on content made by someone else because you copied them, sure but its not stealing.
This is a very old problem. One of my first commercial programs was a wordpress plugin and as you know, you just distribute the PHP source code in a zip file and there it is
You will never sue your way out of this. Piracy will always exist. GitHub will respond to a legal notice but whack a mole is the game and legal notices cost money
The solution in the WP community at the time was variations of the plugin as a loss leader to get revenue with support or to leverage community visibility into larger contracts for work or hosting the platform for others.
If your business model depends on your code being a secret, JavaScript is not a good play. The business model needs to enhance what the code offers since it’s basically a commodity now
There exist many WordPress plugins that are not GPL-licensed, or plugins that are ostensibly GPL but are merely wrapping things (either code or APIs) that are not GPL, which isn't exactly a compliant use.
Whether we like that is not the question I was answering.
I understand, but if I create some code that use no wordpress code and only API access and don't ship it with wordpress, they can't enforce a gpl licence for my code.
Sure but developers would still add licensing checks, hosting some dependency offsite, or other obfuscation to try and force people into paying for the plugin
It just doesn’t work. Anyone who wants to will take it. I don’t see this problem going away
AI did this to every developer in the world and nobody cares. This just confirms to me that software engineers are the biggest cucks that exist right now.
If you think an AI can't reproduce this without it being a copy of the code you are sadly very very mistaken.
I've had an AI reproduce astronomical formula functions without difficulty in whatever programming language I want. Graphical algorithms aren't even a challenge.
Might be time to reconsider the business model entirely, because Pandora's box is already opened.
First of all, thanks Ivan! Happy user of Photopea.
Second, the trademark will help you against the masqueraders, those copying your tool and the Photopea brandmark. That will help with customers complaining about some other modified product. It will not help in case you find someone copying your codebase and putting it out in the open under a different name. For that, you'll need a copyright.
Doing both of these might be expensive but gives you complete legal standing. Companies will have no choice but to take down the copies.
There are 100s of web based photo editors, paid and open source. How do you know they are taking yours, not someone else's or making their own with Ai?
I would imagine they all converge on common features and core implementation foundation
There have been only two photo editors that fully support the PSD format: Photopea and Adobe Photoshop. When a new one appears, which fully supports the PSD format, from an anonymous creator, it is very likely a copy one of these two. And they usually name it Photopea-offline, etc.
Why is so hard for people to post a link? If y'all are going to be making claims, post the links to back it up. Then show how the code is the same. If the original is online and the copy is offline, that would seem to indicate a material difference (without digging into both their code)
This smells a lot like the Laya thing to me, especially with the astroturfing by friends and fans
You should discuss this with an attorney that is experienced with IP law to see what your options really are. IP law is very complex and sometimes very surprising. You need expert legal advice, not advice from the HN crowd.
As an aside, I thought that "cracked" software meant software that has had the copy protection or other access control bypassed or removed, not the alteration of the software functionality itself. If your software was actually cracked then you may have some fairly heavy law in your favor. For better or worse, bypassing access controls (even weak or simple access controls) gets special legal attention.
... they're just trying to get the attention of someone at GH that can do anything OR create bad press that they then have to deal with. But pressuring them on HN to act about their sub-par anything is.. arduous, given their.. tolerance.
Most state bar associations have a free consultation line that will refer you to a reputable lawyer to start with and do basic consultation on where your issue should go and how much it will be. If I had to guess, getting advice is probably $100 and having a lawyer send a letter is $250-500.
IP lawyers tend to be at the more expensive end, typical billing rate in US of $500/hr last I looked. But yes, being able to do a letter quickly is probable.
I was like oh cool... until you mentioned the ads.
I would not fork or re-release proprietary code. I would ask my LLM to write a very rigorous end to end test suite for your tool, delete all the code, then have a clean context LLM re-write the code to pass all the same tests. Then I could publish it under an open license.
Ads are a cancer, and it is a matter of weeks before someone does the above where you have zero recourse.
I suggest open sourcing the code properly without ads yourself before someone does it for you. If you do that someone might donate to you instead of paying for the tokens to clone your work.
Software is no longer a moat and DMCA means nothing anymore.
You aren't. People aren't going to be able to make a living in software anymore, unless they work for a corporation. And even then, that's disappearing as well.
When the whole industry manually punched machine code into punch cards, people were threatened by assemblers taking their jobs, and then later by compilers, and now by inference engines.
The real engineering work that will always be paid for is identifying problems and testing solutions to see what solves the problems.
The substrate in which we use to do that will change, but the job will endure.
Those that just do what they are told however, yeah they are SOL unfortunately.
Creative problem solving is the only skill that will matter anymore.
And how many companies need creative problem solving? Way less and less. The problem is the moat is getting higher. Name any other profession that is kneecapped worse than by the free open source movement and the like. Meaning you can't monetize what you create. Or the usual ways are non-conformant, dictated by the corps and their mindless followers.
Almost anyone learn anything they want now. This all cuts both ways.
If security is a solved problem then anyone that wants to teach themselves enough can move to trying to solve disease, until disease is solved, then we all move on to building enough robots to mass produce enough food to solve world hunger and shelter... and once the needs of everyone on earth are solved at an ever cheaper price until it is free... then I guess we do whatever we want.
Only way to earn a good living is to pivot to solving diseases for a few years until robots solve world hunger and shelter. Then we can do what we want without the money to do it?
Most positive changes in this world happen because of the tiny subset of the people delusional enough to believe they can do so that also happen to be correct.
I feel like trying to better humanity, even if I fail, is a better use of my time than simply saying nothing can be better and giving up. At least by failing well, at worst, the next delusional person can carry the work forward learning from my mistakes.
It is going to be a slog, likely over multiple generations, but one worth the climb.
"I feel like trying to better humanity, even if I fail, is a better use of my time than simply saying nothing can be better and giving up. At least by failing well, at worst, the next delusional person can carry the work forward learning from my mistakes."
If you have the capacity to do that, I.E. a multimillionaire, then sure.
If everyone has unlimited access to food, shelter, medicine, and knowledge then we are left with a tiny subset of compulsively competitive people fighting each other to acquire new forms of entertainment. I would pick that world over this one.
> unlimited access to food, shelter, medicine, and knowledge
That is not the things that can be unlimited. There will always be better food, bigger houses, better medicine etc.
In the eyes of the bottom 30 (or maybe even 60) percent of humans on the planet Earth average American already has the access to unlimited food, shelter, medicine, and knowledge. But good luck to convince Americans that they have those access.
AI may be the biggest change to society since electricity, but fundamentally we survived that transition and on the other side the baseline quality of life is much higher now. This one stands a very good chance of ending the same way.
Doubtful when we're flying toward hyperinflation because of government overspending with zero care for their citizens.
Doubtful when stock prices go up because companies lay off/fire employees.
Doubtful when hiring foreign workers for cheap is strongly preferred over their own citizens.
If you're already a millionaire now invested in tech and S&P500 and have property maybe you'll be alright and maybe you won't agree with this perspective, but my perspective applies to the vast majority of people.
Photopea is lucky that it has a decent amount of revenue. But that's an exception, not the norm. Generally speaking, for new software, the business model of desktop, client-only software hasn't worked well since late 2010s at least, and nobody should expect to run a viable business like that today. There are very few applications you "install" on your computer that doesn't require native capabilities in some way.
Hey buddy, you’d better be careful what you post on a public forum. Sooner or later somebody’s gonna ask their own personal LLM to write a comprehensive test suite for how you respond to comments and situations, move the mouse cursor upwards and to the left to click a button there, and recreate you as legally their property now. If I were you I’d gimme money gimme moneyyyyyy before my big LLM here teaches you a lesson the hard way.
Please rip me off if you can! I would be thrilled. I open source 100% of my work and if people plagiarize it and the net result is my work and ideas positively impacted more people, then that is an outcome I am proud of.
True. I understand the author on the emotional level, but the fact that a lot of work went into the product does not mean that it is that valuable. The author should focus on making the product better - unfortunately (for them) that means inventing a new business model.
A closed source, client-only "desktop" application, especially a web app with obfuscated/minimized JavaScript code, has no real copyright protection these days. You either sell ads, sell it to enterprises, or if you are lucky enough to be able to pull it off, sell a subscription. Not putting the logic on the server in the first place means everything is basically public knowledge.
You seem to be thinking about "adblocker running in browser", since you brought up EULAs.
That's not what OP alleges - they are saying people are redistributing modified versions of OP's copyrighted code. DMCA is an appropriate measure in such a situation, but it's unclear why OP's DMCA takedown was rejected by GitHub. Without more detail, it's hard to comment further
> You want to sue people for blocking ads? Did I read this correctly?
That is an extremely disingenuous and bad faith interpretation of what OP has said and I think you know it. You want to be edgy? Go comment on Reddit.
OP is rightly frustrated that their copyrighted work, that they’ve been working on full time for over a decade, is simply being ripped off by people and GitHub refuses to do anything about it.
Publishing source as client-side JS when millions are out there looking to rip you off at every turn is a losing proposition. And I think you know it.
Shifting blame to GitHub is absolutely idiotic.
Try removing locks from your doors in a high crime area (which is what the Internet is) then being indignant when the police can't stop all the criminals stealing your property.
'losing proposition' is irrelevant. The law is clear in this case, and the law makes Github's obligations exceptionally clear. By refusing to act, if the DMCA notice was valid, Github is breaking the law and forfeiting their safe harbor status.
I'm a solo dev who just shipped my first iPhone app, and reading this is a good reminder of why I went the App Store route. My code ships as a compiled binary, so there's no source for anyone to copy and republish. I pay Apple's cut and complain about review delays like everyone else, but never having to file a DMCA takedown against someone reselling my own work is worth it.
Just replying that I vouched for this post, and to ask others to please restrain their pique and not flag it into oblivion again.
This is a good faith contribution to the discussion, and frankly, the way things are going, the point it raises is something most of us need to consider.
Man, some of the comments this is getting are absolutely wild.
OP, I’m sorry this is happening to you. It must be incredibly frustrating to have people ripping off something you’ve worked on for many years and pass it off as their own work. I would be furious in your position.
I wish I could do something directly to help you but the best I can offer is to echo the best advice others have already given you: it’s time to get a lawyer. That is the one guaranteed route to get GitHub to sit up and take the action they should already have taken on your behalf.
Regardless of what you do now, I think you should be prepared for the upcoming reality that LLMs are going to be able to reproduce software, feature-perfect, in a way that does not currently violate copyright law.
Right now, the settled law is that such an LLM reproduction is 100% legal.
If you really want to protect your software in the years to come, you might have to seriously consider starting some sort of popular political movement to address this issue in copyright law.
Current models can already do a full reproduction of anything with source code available (e.g. JavaScript...), and there's already been some poor-quality Photoshop knockoffs.
> popular political movement to address this issue in copyright law.
Or perhaps the people should admit that copyright, an artificial construct which is not rooted in natural property, was inherently broken and is not (or at least no longer is) a net benefit to the society and simply adapt around it.
I was watching a video talking about how a world before copyright allowed innovation to spread quickly and allowed people miles away to iterate faster. Even if LLMs reproducing feature perfect software is deemed a copyright violation, people will just do it privately and use the software themselves.
I’m personally waiting for LLMs to get so good that I can make music and movies based on my favorite ones. I probably could never release it to the public, but being able to make it and enjoy it myself would be amazing.
There is something similar happening in the game modding communities. One of my favorite streamers had claude write a little mod to change the UI of KSP so it kept with the larger fanciful theme of the game, over being so sci-fi-ish. He didn't like, he changed it, he's probably not going to release it because of sensitivity in the broader gaming ecosystem.
I have agents maintaining several patches to my main tools, not forking, not sharing (some have no interest), personal adjustments
> he's probably not going to release it because of sensitivity in the broader gaming ecosystem
There is basically zero pushback to generated code. All the crazy Minecraft in GTA type mods that came out in the last couple weeks are obviously vibe coded but no one cares because they play good and surprisingly bug free.
If he put in AI visuals as in generated textures then it's different, because that's way more visible and gets labeled as slop immediately. There's also the (accurate imo) perception that AI is taking artists jobs against their will but coders adopted it on their own and benefit from it, so using it for code is ethical from a labor rights POV.
That world worked because the ones doing the research were either self-sufficient hermits (often self-sufficient by necessity as they were outcast for "being mad"), financed by the Church or financed by a rich person (usually the fiefdom's ruler, sometimes independent wealth).
Copyright, patents and IP are the evolution of our (Western) way of converting research into a form of financial investment.
Patronage and support of the arts (and sciences) was a great value proposition for Churchmen in old times. You could commission works of music or sculpture or stained glass or what have you, and these were of course well-fitted to be installed or performed in the confines of your church and serve the liturgy. So they were collective goods that were enjoyed by many; they attracted locals and they beautified their surroundings, and they encouraged pilgrimages and stimulated income if you could become particularly distinguished and attractive, based on the beauty lent by your artisans and artists.
And a big church could employ lots of them, and thereby stimulate the economy. It seems that the Baroque Era and churches crammed to the rafters with art, may be an artifact of a very good job market for those architects, craftsmen and artists!
Yeah... you could copy some sheet music and share it around, but it still required skilled musicians to perform, play and sing it. And nobody was taking photos or uploading JPEGs of your art and sculpture, so it was fairly locked-in that people needed to visit, and see it in context. So it stood to reason that you could probably reconstruct Noah's Ark from the fragments of True Cross that were circulating around Europe... and how many fingers did your favorite saint really have?
Copyright-free church economics have sort of fallen apart since then. However, museums, arena concerts, theaters and the rest, they have all taken pages from the Church playbooks. The fact that a church can still draw in hundreds for a show with great production values, every week or daily, seems dull and unremarkable now, but a good rock concert or museum collection can evoke the same "goin' to church" fervor in people who like that kind of stuff.
My one big issue there is that "adapt around it" tends to look like cryptic black box "Software as a Service" because that gives you a solid moat against competition / reproductions. I would like to be able to pay for software whose function is wholly transparent to me.
That said, I mostly end up using open source for the same reason
> Right now, the settled law is that such an LLM reproduction is 100% legal.
How so? Interfaces are not copyrightable, but that it not the same as dissecting a js bundle and copying the implementations. Are we sure these LLM are keeping sanitary habits there?
If you only used the output of an LLM, then you don’t qualify.
But, the use of LLMs is not disqualifying. To qualify for copyright protection your work simply must have a sufficient degree of human authorship.
However this is just about protection, not infringement.
If you use an LLM to generate something and that LLM just happens to output something that another human wrote, you may be liable for copyright infringement.
I feel like I need to nitpick a little:
Models don't need source code available to reproduce software. See all the "full decompilation" projects cropping up. There's no putting this genie back in the box, because LLMs can also "refurbish" a project enough that it ceases to look like the original. People don't bother now because they don't have to, but in a world where they'd get hit with copyright notices, they would.
I will say that a lot of the "full decompilation" projects popping up are honestly crap - some are good, but a lot of them just build something that makes for a good screenshot or promotional video.
I'm not convinced we are actually at the point where something like Photoshop is trivial to rebuild. That involves a lot of manual QA and the expertise in actually knowing how everything should work.
That said, give it 6-12 months and I won't be surprised if they can one-shot "create a future-complete clone of Photoshop, make no mistakes"
There was a major lawsuit about this involving Google vs Java years ago. Copying code might not be legal, but an LLM can use the application, learn how it works, write unit tests around that, and then fill in code that passes those unit tests.
The current fun loophole is to have the LLM decompile the existing code, build unit tests around that, and then have a different LLM model build the code that satisfies those tests.
Either way, you can absolutely get a "clean room" result from an LLM.
> the settled law is that such an LLM reproduction is 100% legal.
My understanding was that re-invention without copying any code is legal. But scraping code from the browser and re-using it is not. I'd love to know how that plays in the courts with LLMs, as their entire model comes from copying code as training material, not writing new code from scratch.
Sorry to have been unclear - I did mean "clean room". But an LLM can easily jump through the loopholes currently required for that.
Regular humans train on copying code too (Stack Overflow, etc.) so unless they were trained on that specific codebase, I really doubt you have any sort of legal standing. And given how little compensation the authors got when their work got trained on, I wouldn't hold out hope for a big payout even then...
> based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201
Sorry GitHub, that's not for you to determine, as you are not a US judge. They should never have replied like this IMO and this behavior opens them up to liability for not properly handling DMCA procedures.
Proper DMCA 512(h) notices (assuming OP's was proper) require the host (github) to remove or disable the content first without even attempting to verify the claims.
Then the repo owner has a chance to challenge the notice. If they choose to do, they're basically required to publicly doxx themselves first, by nature of just going through the motions of the judicial court system.
If there was no challenge after a set period of time, then the content stays down.
If there was a challenge, it stays down until a court decides what happens next.
the musicians love it when their original work is DMCA'd by bad actors and YT takes it down and never answers the appeal /s
two sides to the coin, we'll hear about how some evil corporation used their influence to have a legitimate project DMCA'd and HN will have the opposite reaction on that day
something like "jury duty" from the community seems an interesting idea for a middle path, if we want better systems, we'll all need to contribute a little to making it so
The section 1201 text was from the email OP received, I was just quoting that verbatim.
But 1201 deals with circumventing copyright protections and AFAIK isn't related to DMCA takedowns, but 512(h) is what I've seen typically used for DMCA notices instead, to get the identity of a poster in order to sue them (since the ISP itself is exempt as a conduit), so that's why I mentioned what's required for it.
> Thank you for submitting a DMCA takedown notice. We've reviewed the information you've provided, and based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201.
Did they actually republish you code or were they just creating wrappers that download/cache the code from your website to run locally?
Can you post the actual link of the repo? You'd get responses with more context.
You had commented on the photocraft post prior, so if it's that, then it's a bit muddled. It's a LLM based re-implementation and not a copy of the code made open. So the argument would be weaker there, and you'd really need specific code samples to make a case of copyright infringement. Photocraft not "piracy" as is normally understood, which is the exact same binary, optionally with the license protection removed.
First off, let me get this out of the way - I am not a lawyer. If you want a legal advice talk to a lawyer.
Second, I am sorry this is happening to you.
Third, based on GitHub's reply, specifically
> we're unable to confirm a violation of 17 U.S. Code § 1201
they took your submission as 17 U.S. Code § 1201 takedown notice. Maybe you specifically stated this. Maybe it was implied. This is likely not what you want and GitHub's response is likely correct. The reason for this is that § 1201 prohibits circumventing a technological measure. The JS you host on your public site, even if obfuscated, very likely does not qualify for this protection. Another detail - the reason it took long (a month later according to your post) is that after the youtube-dl fiasco, they committed to manual review, legal and technical, of every 1201 takedown notice [0].
Fourth, if you believe these copies are sufficiently reproducing your copyrighted work,
what you likely want to do is file a standard copyright infringement 17 U.S Code § 512(c) takedown notice. This still goes through the same DMCA report flow but it should result in a less stringent review process and a faster response.
Fifth and finally, consider asking your favorite LLM to get more context around these laws. Good luck!
1201(a)(3): "As used in this subsection-- to 'circumvent a technological measure' means to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure, without the authority of the copyright owner"
Indeed, a 512(c) takedown notice is the way to do it. GitHub is extremely unlikely to ignore it. I run user generated content websites and would never ignore a notice. You definitely don't need to hire a lawyer to write it either. Just follow the notification guidelines in 17 U.S Code § 512(c)(3).
It is not illegal to build a service with the same functionality.
So you are going to have to prove their code is a copy of yours, not just a copy of the functionality.
In Google vs Oracle, APIs also aren’t necessarily copyright able:
“So long as the specific code used to implement a method is different, anyone is free under the Copyright Act to write his or her own code to carry out exactly the same function or specification of any methods used in the Java API. It does not matter that the declaration or method header lines are identical”
I am in the same situation where people are hosting copies of the software for commercial use in companies. Even as big as Tencent. That is not allowed with my license and they also went to remove the code that does the license check on application startup. GitHub’s response so far: “please give an explanation how they can become conformant so that the users can fix this.”
Oh jeez. I'm not automatically assuming that the Chinese did this, but Chinese IP thieves did crap like this for decades, and most of the victims were unable to do anything. There were posts right here on HN like "Chinese company stole my app/game" and with AI this will be an even bigger problem.
Meanwhile AI refuses to touch photos that contain anything that remotely looks like Mickey Mouse.
You're really pointing out a couple fundamental principles where growth has been able to occur one layer at a time over a nonsensical foundation.
This doesn't lend it self to a sensible solution.
There's no way that computer code should have ever had any legal similarity to entertainment properties like Disney characters.
Plus so many people don't want to pay any attention to the way there's a big difference between entertaining software like games versus things which are needed before "machines" will even (barely?) run, or run more superbly which is not the same either.
And there's no way any "rights" should exist for an extended period.
Among other things these need to be corrected more so than ever (or AI will do it for us). The problem is it all needs to be sensibly reversed not gutted in one big shockwave. But AI is here to shock. It doesn't even take superintelligence, if the people who gradually caused the problem over the decades were below-average things would have come out better as long as their objectives were less predatory.
Hey guys, thank you all very much for your comments! I just woke up, I did not really believe my post would get this much attention, so thanks!
Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.
I think I will try solving it with a lawyer. But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.
> But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.
I think anybody in any line of work or life would like that. It's however unlikely to never run into an issue where a lawyer is really needed, so don't hesitate when you realize you need one.
I could find are a bunch of Photopea repositories on GitHub, but the authors are all either from China or Russia, so getting damages for infringement will be difficult to enforce. Hiring a lawyer sounds like a waste of money to me.
In my experience GH usually does 512(c) takedowns in days; so it taking a month is quite abnormal. OP’s posted response suggests he didn’t file a copyright takedown but rather an anti-circumvention claim; which is a bit special in DMCA law, and generally best avoided when you have merits to do a regular 512(c).
We also don’t have details of the repo. The author has commented on another project that claims to be a LLM _re-implementation_ of Photopea, without directly using source. If that’s the case, it’s entirely understandable why GitHub won’t take it down.
Sadly though, you have to do the cost/benefit analysis of the legal process and your likelihood of recovering anything.
I spent $18k in legal fees over a $22k claim in a construction dispute. I won the suit and was awarded legal fees. So I'm owed $40k plus interest. I've collected exactly $0. The last lawyer I spoke to said I need to cut my losses in legal fees at some point because from a practical standpoint, winning damages isn't the same as collecting them. Especially if the defendant isn't local and has few assets.
>Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.
A talk with a lawyer would be advised. But this is money you may not want to invest.
You could just go on, keep your product improving and proof this way that your solution is more worth than the copycats out there.
You just realized how it is to be a valuable target.
I would suggest that, instead of trying to complain about the people copying your products, which I think is practically impossible to avoid, and even from your own experience preventing it has led nowhere so far, you should focus on making sure that your version of the product is the best one. So that the people will naturally use it instead of those repackaged versions.
> take the Javascript code from my website, remove all ads from it
I would assume that this might be one of the reasons why people are modifying and repackaging your product. I would suggest to remove that incentive. So that the people will have no reason to repackage your product because it has annoying features. And so that they could use it directly and be happy about it.
Which to be fair, would maybe actually work, and there are political positions that want to achieve such an economic system. Not that I would necessarily agree with them.
I do not understand how what you have suggested could be considered as an appropriate analogy.
No one implied that the author should offer their product for free. I merely suggested that they need to focus on other aspect of their product rather than the mechanical software parts because they can no longer be the differentiating factor. Precisely because they could easily be recreated or copied.
>you should focus on making sure that your version of the product is the best one. So that the people will naturally use it instead of those repackaged versions.
Do you have any concrete ideas for how to do this or are you just saying this to defend piracy?
I think we're going to see a lot more of this going forward.
I think we're also going to see the strategy to be to remove the processing and magic sauce from the client and move it to the server where it can't be decompiled and rebuilt with AI.
> because it would be doing so without having access to the source
I find it unlikely that photopea was never scraped for AI training considering they are looking so hard for new material they started buying up and scanning old books.
When it can do that, the people can also describe the output, i.e. the fact that your original website even exists is irrelevant for what people are able to do.
Apps like photopea exist because of client side processing. They shift cost to client compute and that makes them supportable by indie devs.
I'd wager we will start to see more web apps like this have greater obfuscation and dependencies on operating on a particular domain. Sure AI can help to circumvent many things, but at a certain point they pay-off may not be worth the effort.
Since these clones already exist, it means that even if Photopea moves to server based (which it should have been in the first place), the code is around and will work forever.
The magic sauce haven't been in the client for many applications for years. Google barely has any application that runs on desktop OS even though they could have released them.
>, it means that even if Photopea moves to server based (which it should have been in the first place),
It's a 1-man operation so it may have not have been financially viable to architect the app as server-based.
- server-based : must invest a lot more money in server farms and extra disk storage, or pay high AWS cloud fees. E.g. if a million users do a blur or denoise filter, all that cpu processing has to happen on the servers, and massive disk space to hold the intermediate files, and extra bandwidth costs to send the changed bytes back to the client.
- client-based : just ship Javascript blobs to end users' web browsers because the blur/denoise/etc filters happen on the desktop.
Also, this type of pixel-editing software still needs a ton of client-side Javascript to behave like a Photoshop clone because users want to see interactive changes as they dynamically slide the blur/noise/etc settings. Round-tripping that with extra server latency is not a fluid UI experience.
We can't confidently replay the past and say that starting it as server-side app from the very beginning means he'd have the same $million in revenue today. Instead, the extra server costs and UI jankiness could have doomed the project.
It's a business decision, and I'm not sure if they made the right decision. Most client-only web applications are open source because they know there is no business in selling it as a service. Photopea somehow is an exception, but its business model is getting questionable which is not a surprise at all.
It's also possible to use a combination of cloud based and local computation. Figma is doing quite well in that regard, especially with the use of WebAssembly. No doubt that potentially means more work, and potentially forcing users to create account etc. But hey, that's a business decision as well. If you don't do anything but just keep everything in JavaScript, this was going to happen.
Thanks! One is Ticket 4822535, another is Ticket 4726557.
Github did take down this https://github.com/spooknik/Photopea-Appimage and other repos in the past, but now, I feel like I talk to a robot. I am happy to hear that they have real employee! :D
I accidentally stumbled upon malware disguised as Roblox hacks some three hours after the repo was created. It took Github 25 days to take it down. Granted, the initial automatic reply admitted they were "experiencing high volumes".
Yeah I’m a huge fan too and pay for a subscription. It has basically fully replaced Photoshop for me for at least a few years now. Between Inkscape and Photopea I haven’t touched an Adobe graphics app in years.
T.I.L. about photopea, and I have disabled Ublock Origin for the site. I see a static 'slide show' column of non-video adverts on the right hand side of the screen - about 10% of screen width.
Sorry to hear this is happening. One thing that might be helpful is to port it to another language and build as wasm. Agents are pretty good these days at stuff like this might even end up being faster.
I enjoy and use photopea just as much as everyone else here, but isn't the whole premise of photopea to offer a near-exact reproduction of photoshop's UI/interface and functionality, such that users who might otherwise be paying Adobe customers just use photopea instead?
This reminds me of LLM companies scraping the entire internet and destroying millions of books to scan them in bulk quickly and then complaining about others performing distillation attacks against their models.
It's fine to be unhappy about people coming to you with complaints about forks of your software, but if the premise of your project is "we made a near perfect clone of Photoshop so you don't have to pay for it", haven't you kinda ethically ceded the right to complain about other people copying your software, even if you managed to stay within the confines of copyright law?
If you're building on other people's ideas and work, don't you owe the world a duty of reciprocity in openness?
Bring back look-and-feel copyrights and the Whelan interpretation of software copyright. Programmers have gotten away with stealing the patterns for entire programs, producing identical clones of another company's valuable IP, for far too long.
I have a feeling that Whelan is going to become relevant again as judges realize that people are using AI to copyright-launder major applications and games (a practice for which I'll coin the term "sloppylefting"), effectively stealing them in a way that cannot be prosecuted using the current very strict interpretation of copyright law with respect to software.
It's inevitable if your entire product is statically hosted and pulled into their browser. They didn't even need AI to do this, they could have just done it by hand anyway.
With all due respect: people should be able to do this. Copyright as a concept applied to code was always a god-awful idea, DMCA especially. And for JS served on the open web it's plainly comedic.
Someone can always make a new repo without redistributing your code, sourcing and hot-patching it directly from your domain. GitHub deleting this repo won't ever fix it, you're playing whack-a-mole and doing free PR for these repos here on HN.
We seem to forget that this website is called Hacker News.
I would like to think more deeply than this response.
I do not want enshittified software that creates a bogus need for a server in order to extract licensing fees from me. I prefer to pay for locally run software, paying in ad views if I have to because that’s the micropayment system we have ended up with.
So is there a path to an ethical, viable business model for the author?
In an era of slop, quality is king. I honestly think the author should just ignore the cheap clones and continue selling quality software. The idea that the clones are perfect, bug free, or will continue to be maintained and hosted is a fantasy. There will always be people with low incomes in the third world trying very hard to get something for nothing/cheap, and they are the worst customers. No loyalty, highly intelligent, and will drop you immediately if a competing offer is 1% cheaper or offers what they need for free.
Adverts are likely a poor business model here - if you want to sell to professionals and creatives, the visual look of the software matters. It should really be subscription or one time licence
Sure. One example of a path, that many people are already doing, is a system like Patreon.
The old model of server-locked licensed software is going the way of the dodo pretty fast right now, though people may not realize it if they're not hunting for alternatives to the old guard suites yet.
And while personally I agree with the commenter above you for personal reasons, I also think that the OP is missing that while the people who've ripped their js tool may have done so directly from their site, no one certainly has to any more: they can likely black-box something similar pretty quickly, at which point the author's DMCA moat is gone.
> So is there a path to an ethical, viable business model for the author?
Yes and no. An ethical business model for software in this world must be built on a long process of collecting good faith from customers, it just doesn't pay well enough compared to the ones that shatter said faith (adware, exploitation, dark patterns). I think the software moat will be more and more based on social capital. People are happy to pay for the software if they know for a fact that company/person behind it isn't being hostile to them. Look at Steam as an example of this. And you can always open source your code, and still make money through the means of good faith. Is it actually viable? I don't know. It depends on how much money you want to make.
I don't believe that "ethical" and "ad supported" are compatible. Harvesting our private data and selling it to the tech-dystopia to further curate profiles about our every move can never be considered "ethical", imo.
From my perspective, those people who are taking this public client side code (not emulating any kind of server), and removing the privacy nightmare, are actually doing good for society. The software is more usable, more performant, and far more secure when they are done. The only harm is the authors ability to monetize.
I don't think it's possible to have a fully client-side web product and be able to enforce strict guardrails on the use of the code. Regardless of ethics, it's just not feasible. What you give up by delivering the full source code to the browser to render is control over the source code.
If the author wants more control over their source code, and easier monetization, they should compile a binary and distribute that. The guardrails protecting source code, duplication, and copyright infringement are much more clear. That's just the harsh reality of delivering source code to clients.
> Copyright as a concept applied to code was always an awful idea
That may well be, but as long as that concept exists in law, I sure would like every developer to be able to benefit from it equally, not just Microsoft and Adobe.
> Copyright as a concept applied to code was always a god-awful idea, DMCA especially. And for JS served on the open web it's plainly comedic.
Why is it comedic? All of my own code is open source and freely available, but protected by copyright -- namely via the GPL. Copyright is what helps ensure that we retain open code, and ensures that it propagates openly.
How much further along the enshitification path do you think Android would be, if Google wasn't bound by the GPL in so many areas? Copyright with code is not only fair (why on earth would creating code be different to creating anything else?) but it is what keeps so many things free and open.
Hard question to answer. If there were another phone operating system, built on a combination of permissive and proprietary software, from a company which notoriously avoids 3.0GPL like the plague, and minimizes use of 2.0GPL whenever possible, then we'd have a fair basis of comparison.
I think GPL was though of and is an answer to the idea of copyrighting code. If there was no copyright for code, there might not be any copyleft license. If we were all allowed to freely copy and modify and redistribute etc., then there would be no need for licenses enshrining these rights.
Have you considered not serving ads on your website and making it more accessible to discourage those from wanting to tip it off and strip the ads? I can tell you from honest experience, if I were a user of your software/site (which I'm not) and it had ads, I'd be dropping them on the floor pronto (probably with AdGuard). I hate ads, I despise what we've done with the Web/Internet with all shit Advertising and Tracking shit™
I don’t like ads either. So I just paid for a local image editor and use that one instead. The developer of the product gets paid, I get a great ad-free image editor.
IP lawyer here - I can't give you actual legal advice because you aren't my client, but generally, you have two options here, neither of which will be surprising, or very satisfying:
1. Pay a lawyer or firm that specializes in this sort of thing to play whack a mole for you
2. Accept it as normal losses and ignore it.
Contrary to others claims here, it is not a 500/hour thing to do #1 when dealing with firms that specialize in this. it probably would be if you just hire a random one-off IP lawyer to try and deal with this particular instance.
Trying to deal with it yourself will be increasingly frustrating and time wasting for you. You will also never be able to prevent someone sufficiently motivated from doing stuff like this to your software.
Unless you want to spend your time dealing with those folks instead of building the software, you should hand this part off - it's not a good use of your time, value wise.
Put another way: most companies farm out processing of this sort of request to high volume low cost processing teams. Or AI. Or both. For you this is an important one off. For the person processing it it's one of a hundred tickets they are handling today. You are not going to get very personalized attention and consistency.
I don't claim this is how it should be, etc. I simply claim this is how it realistically is. It would practically require legislative change to have a different thing happen here and while interesting to discuss, that seems outside the scope of your questions, which seemed more practically oriented
I've spent 0 seconds googling this so excuse the dumbfuck question but: is there any precedent or convention for writing off the stolen goods as losses? I'm pretty sure physical goods from businesses qualify but what about this??
Digital losses to piracy sounds like something that would be impossible to quantify.. even if they can prove that people are downloading these pirated copies, that's not proof that the downloader was ever going to pay for the software in the first place.
Physical/digital has the same answer, just different effect.
As a general rule, you can write off what it costs for you to make something, but not what you lose from not being able to sell it.
Which means for physical goods, you write off the cost to make them, and for digital goods, you can similarly usually deduct development cost to make the software.
In neither case can you write off the amount you would have made had it not been stolen/sale had not been lost.
The practical effect is that because physical goods have a per-unit to-make cost, and most digital goods don't, physical goods get written off per-unit-lost and digital goods do not.
At least, this is the most general answer I can give you for that level of general question.
Could you just make a CICD process that for each minting of a software license it cost a person's time to review and accept and then the wages for that individual become the write off. I.E. Convolute the software delivery process so that like a physical good, it has a per-unit to license cost to recoup. Or would that be argued as it could have just been automated and it's not really a real loss leader just bad policy?
You don't lose this time for pirated copies of your software, as I assume you aren't taking this person's time to create a license for pirates.
To write something off you have to actually lose the money - writing off is a process to decrease your taxable income by your expenses, unless you're inventing fake expenses (read: performing tax fraud) it doesn't generate a greater amount of money than the expenses.
What I am hearing is “there will be no justice here for you.”
The bad guys are winning, because the good guys have no legal recourse. The only practical solution is vigilante justice, but that makes you a bad guy.
In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice?
Let's separate criminal and civil here, because this is all civil law.
Civil law systems largely aren't about "good" or "bad". Justice there isn't "good guys win" and "bad guys fail". It never has been.
It's about trying to reasonably resolve disputes. That's all. Civil legal systems were created not to enforce morality or social order, but instead to formally resolve disputes.
The system is pretty good at doing that. It will never resolve all disputes, let alone resolve all disputes in an "optimal" way (for any possible definition of optimal you come up with). It only tries to do a reasonable job of it.
If your expectation is that the law will stop "bad" actors from acting "badly", i think your expectations are out of whack. Yes it gets tried, but it is a fairly miniscule portion of the system overall, and generally not a very successful part of it. It's also remarkably recent in the history of legal systems. It is a quasi-political thing that the legal system simply isn't good at dealing with, and really is not a good match for it. I think results bear that out so far
You can take that for whatever you want - I can only tell you why the system is there, historically and currently. That doesn't mean you have to like that idea, and you are welcome to rail against it.
> In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice?
Guess why trust in democracy itself is eroding everywhere and why even executing a health insurance CEO on broad daylight is not just widely approved but widely beloved.
The rich can get away with anything (Trump's claim of "I could shoot someone on 5th ave and get away" is pretty realistic, to say nothing about the Epstein crap), but if you are poor or, even worse, an immigrant - pray to God to help you because not just will no one else help you, but in the worst case you might end up getting fucked over for seeking help.
Well, shouldn’t that be up to the original developer? He made a product and let people use it for free. But no-one is forced to use it. And there are other image editors without any ads. Some are proprietary, and some are FOSS, e.g. GIMP.
Since you're here and on topic, a question that has been at the back of my mind because I feel that soon most software creators will be in this boat, with AI rapidly becoming able to clone software from observing behavior alone:
Are patents the only real IP protection left for software?
And would a patent (assuming this application had something patent-worthy to claim) help at all here? As in, in addition to sending a C&D maybe also including language about patent infringement would be more effective?
I know that patents are unpopular for many here (including you, IIRC!) but I think this question is extremely important, especially to anyone who wants to make a living purely off the software alone.
Remember: if no other moats or business models or funding models lend themselves naturally to the software in question, anything bolted on is pretty much already on the slippery slope to enshittification. A mechanism that encouraged people to compensate fairly for the value provided by software would be better for the Internet than what we've got going on today.
The only effective protection for software IP is hiding the logic on servers you control (SaaS). Anything released to execute on client hardware can be decompiled and cloned. This has always been the case but LLMs have made the issue more obvious.
there is no more software IP. ai does not need source: it can infer or deduce the logic or algos. and in the case of private software dont think it hasn't been sucked up too
Agreed, only I would rephrase it as, "hiding logic on servers is the best technical / non-IP protection for software" -- consider that IP largely exists to protect things that other means cannot!
But as sibling comment indicates, even that is no longer a guarantee. There are demonstrations and anecdotal accounts of reverse engineering entire features or even small applications, including the backend code, by pointing an LLM at the web UI: https://www.thoughtworks.com/insights/blog/generative-ai/bla...
This is why I'm thinking that patents and other legal means are likely the only way forward to protect software that does not have a natural moat, like network effects or some huge data advantage. That is actually a huge amount of software.
My concern is that without proper protection software without such moats, this will create incentives for people building them to adopt less-than-ideal means of monetizing their work, e.g. the things that lead to enshittification.
You are the scourge of Earth and I hope you stop recommending how to "whack" developers. People like you are basically the mafia for Big Tech. I have been targeted by your industry for doing nothing wrong multiple times.
just move crucial bits in another language and use webassembly. so good section of your code is in compiled binaries hence blocking anyone stealing your IP. also at the moment they just change some bits I don't think it'll be long before they can just recreate a new project with different code but with exactly the same functionality and then you got no protection afaik(although not a lawyer so not 100% sure).
> just move crucial bits in another language and use webassembly. so good section of your code is in compiled binaries hence blocking anyone stealing your IP.
Can't you just steal the entire WASM code just as easily? I mean, I guess if the ads are stuffed in WASM that becomes a problem. But LLMs are pretty good at reverse engineering. I can't imagine it would be too much effort to get them to take the ads out, or to replace your ads with their ads.
> take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download
Remember that there is still quite a bit of friction to doing that, and that many people have better things to do than jump through those hoops.
In addition to the "hire a lawyer" comments in this thread, I suggest building in some heuristics that detect when Photopea is running outside of your domain. They don't need to be "foolproof," but add additional friction to pirating Photopea so that less people will jump through the hoops.
Some historical examples:
- Commercial software in the 1980s and 1990s would burn a hole on the disk, and the software would look for the error when reading that sector.
- Donkey Kong Country would detect that it was pirated by reading the amount of RAM available. (Because SNES backup systems had slightly different runtime properties than the real cartridge.)
More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.
---
Finally, you could consider a business model that relies on server-side functionality for revenue or stickiness, that's hard to replicate merely by pirating the software. (IE, some kind of server-side storage and sharing system.)
> More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.
This is a very frequently repeated point, which is invalid.
Crashing pirated versions do not affect the reputation of the original. It’s an urban legend.
People using pirated versions are perfectly aware of the fact that they are using butchered versions of the original. So when it crashes, chances are it's because of a botched DRM bypass. It's an obvious connection, has always been.
Techniques like what you describe made a little more sense when the means to even figure them out were less feasible for the average person, especially before the web had much information on reverse engineering, when powerful debugging tools weren't as accessible or free.
Today, there is little point in trying to slow down software pirates. At best, adding an arbitrary piracy detection only adds anywhere between mere minutes and a few days to the effort to crack software. This is true absent AI assistance or even a meaningful understanding of ASM outside of logical JMP instructions. The author will likely waste more of their time implementing anti-piracy techniques than a software pirate would figuring out which function call results in the program exiting abruptly. I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities. This is in spite of various licensing and contextual checks throughout.
It would slow down a pirate more to have a program modify or decompress itself in memory, but that class of techniques is still more trouble than it's worth. Experienced pirates already know how to deal with those traps. The timeout thing you mentioned is clever, but the type of person who knows enough to disassemble software would think to themselves "wtf does it crash after 5 minutes?", immediately investigate, and identify the source of the crash.
Having a license check is the only thing authors of software should bother with. It provides most people a framework to consider whether they should pay for a product. Most people won't download potential malware from a sketchy website if you offer your product at a fair price. Those who either know how to crack apps or refuse to pay will keep doing what they're doing.
tl;dr Don't fool yourselves into thinking you'll outsmart a kid with Ghidra installed by throwing a glorified if-statement in their path.
EDIT: I'm speaking in the general sense. The same principles apply to an app that runs almost all of its logic in the browser.
> I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities
There are some, with code consistency cross-checks and such. Cracking them with static code patching can get very time-consuming. Patching them dynamically works, but some have checks for that too. It's not common though for sure.
Yeah, I'm sure they're out there, but it's very rare in my experience. I'm a micro-brain when it comes to cracking software, and I've almost never encountered this, whether it's small fry software or something from Microsoft or Autodesk. There was some software with debugger detection I came across once (can't remember which it was), but that's the kind of thing where lots of existing workarounds often exist by other crack-ers.
I'd recommend taking a look at DRM for games. It's been a while since I read anything, but AFAIK Denuvo is still effective enough to protect newly released games for weeks.
I've spent some years in gamedev and doing PC versions was a big part of it. I have seen countless attempts at 'code consistency cross-checks' and they all have been defeated. The only thing that came close was Denuvo. You may want to read up on it before dismissing it. It's sad that folks here will downvote and hate anything about it. What it changed is that publishers got their money from people playing on PC and some of it was spent on developers to actually improve future games =)
Also get ye some trademarks. Make sure your logo and branding colors are trademarked in combination with the name Photopea. Use the logo and branding colors more places.
It won't stop AI thieves cold, but now they'll be in violation of two kinds of law unless they do a bunch more work to rip out all the trademarked branding.
Finally, move beyond ads as your business model.
An ad blocker removes the ads from your website, and still leaves you paying to host the traffic. In a way it's worse for you than what unauthorized mirrors are doing. You're seeing that there's unmet demand for what you are offering, so my advice is: figure out how to capture that demand. Why aren't those people taking the deals you're offering them?
I took the liberty of disabling my own ad blocker to do a little research and HOLY COW THESE ARE BAD ADS.
Let's lay out the problems:
- Something is horribly mangled in the ad loading code. The ads flash in and out of existence, and cycle through at breakneck speed, ~5 seconds per ad. Between the flashing in and out and the flashing different ads, it is not possible to do serious work with this going on.
- Many of the people who don't have a photo editor on their device are using touchscreen devices. Many of those people are right handed. For them the actual photo editing tools would be largely impossible to use without accidentally clicking a giant ad which takes up the whole right side of the screen, at which point they would no longer be able to edit photos. Once this happens to you 5 times or so I imagine you start to get very angry.
- Because the ad doesn't fit into the UI at all, you're wasting huge amounts of the screen and impacting productivity proportionately.
So I guess my final advice is: if you don't respect your users, I don't know why you would expect them to respect you. Offer a better deal and more people will take it.
As for how to do better ads, I imagine the best kind of ads would be those where you have a pre-existing relationships with providers of services: photo printing or cloud storage or whatever. When you send them customers who buy things, you get paid. You can then make the ads feel well-integrated into the product, like they're there to help the user. Fewer people should then be willing to go to the trouble of tearing them out. As a bonus if the promotions are built directly into the product, ad blockers won't block them either!
This is a really weird take. OP worked on this during all of their free time for over 10 years. And it finally took off into making a solid revenue for them. This is a rare success story for an indie developer. We should be supporting them. It would suck for anyone to get their life's work stolen and given away for free, which is what is happening here.
-Another indie developer who hopes to have 1/100th the success that Photopea has had.
The 3rd U.S. Circuit Court of Appeals recently ruled [1] that using AI to train on a competitor's copyrighted material to build a competing product is _not_ fair use. This is a recent ruling (September 30, 2026). GitHub policy has surely not caught up yet and who knows when it will.
> Do you think I should look for a lawyer to deal with it outside the digital world?
Absolutely. This is a copyright infringement case and there is now an appellate precedent to cite. Gather as much evidence as you can and speak with an IP attorney.
How is this enforceable with llms if they train on generalist material, which is already the case?
I don't think it's enforceable or even applicable here. "The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content "
You're right that this is a copyright infringement case, but I'm not sure if AI is relevant here, as it seems like a pretty straightforward rip-off.
Also TFA is about a much narrower ruling than it first seems:
>The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content — and the appeals court said in a footnote that concerns raised by the US Department of Justice in a copyright lawsuit against OpenAI "do not apply here."
question: the code on Github is an issue (plenty of answers on that), yes, but is people hosting copies of your service a bigger issue?
In other words, they are probably similar people that do it without publishing on Github...
hey there. fellow indie dev here. i feel you, i see copyright and ai slop ripoffs on the daily. in fact i used to be most upset seeing my opensource code show up in much bigger commercial projects unattributed (looking at you microsoft) but im here to tell you the real answer: you have to compete. you have to compete against the slop and the clones just like youre competing with the original ps and the gimps and the kritas already. it doesnt seem fair, it seems harder, and it is. but thats the truth. ai is out of the bottle. you can still make a better photopea than some dimwit ai and the loser trying to publish their clone, because you think about and obsess over and care about your product way more deeply. that manifests. and you might say why obsess when it can just be copied. and now you sound just like metallica did in 1999. welcome to 2026
B4uler5 | a day ago
Hope you manage to get it sorted but I have no idea how that would go down at this point. I’m sure at least one of them could claim they copied it off the other ones and then you’re shit out of luck.
seanw444 | 22 hours ago
ianberdin | a day ago
I've seen people on Reddit writing things like, "Come on, what's the big deal? AI can write any code now." I disagree. There are hundreds of thousands of lines of code here, very complex code, which even AI wouldn't be able to write on the first try or in a single day. So this person stole this code from Photopea and built a product on top of it.
sneak | a day ago
flourish_dev | a day ago
wafflemaker | 15 hours ago
Headspace updated it's privacy policy info recently, which got me to have it checked with an LLM. And it turns out that what you're doing on $100 per year meditation app is still being sold to anyone willing to pay. Using headspace lost it's charm. I wonder if Andy ever agreed to this.
buckleyourshoe | 22 hours ago
https://www.reddit.com/r/Bard/comments/1wxmqpt/ive_created_o...
Modified3019 | 13 hours ago
sneak | an hour ago
otterley | 16 hours ago
DaSHacka | 15 hours ago
calgoo | 14 hours ago
otterley | 8 hours ago
binlog | 22 hours ago
mingus88 | 22 hours ago
You will never sue your way out of this. Piracy will always exist. GitHub will respond to a legal notice but whack a mole is the game and legal notices cost money
The solution in the WP community at the time was variations of the plugin as a loss leader to get revenue with support or to leverage community visibility into larger contracts for work or hosting the platform for others.
If your business model depends on your code being a secret, JavaScript is not a good play. The business model needs to enhance what the code offers since it’s basically a commodity now
TiredOfLife | 17 hours ago
SwellJoe | 16 hours ago
RobotToaster | 14 hours ago
coldcity_again | 12 hours ago
SwellJoe | 4 hours ago
Whether we like that is not the question I was answering.
Tomte | 16 hours ago
0x073 | 12 hours ago
RobotToaster | 11 hours ago
My understanding is because of the way PHP works all plugins are directly interacting with the wordpress code.
topham | 11 hours ago
Commercial plugins are a thing, next.
0x073 | 5 hours ago
mingus88 | 6 hours ago
It just doesn’t work. Anyone who wants to will take it. I don’t see this problem going away
berofeev | 17 hours ago
But wow, how do you stand a chance in stopping anyone when your code is all there freely available in the browser
croes | 16 hours ago
Because it is trained on code of people like Ivan
Uptrenda | 14 hours ago
topham | 11 hours ago
I've had an AI reproduce astronomical formula functions without difficulty in whatever programming language I want. Graphical algorithms aren't even a challenge.
Might be time to reconsider the business model entirely, because Pandora's box is already opened.
rvz | a day ago
Use a trademark.
[OP] IvanK_net | a day ago
fakedang | 23 hours ago
Second, the trademark will help you against the masqueraders, those copying your tool and the Photopea brandmark. That will help with customers complaining about some other modified product. It will not help in case you find someone copying your codebase and putting it out in the open under a different name. For that, you'll need a copyright.
Doing both of these might be expensive but gives you complete legal standing. Companies will have no choice but to take down the copies.
LoganDark | 16 hours ago
nixrobot | a day ago
Something else is needed. If the code is basically open, then there is no technical protection. Remove tens of those repos - hundreds might appear.
fg137 | 11 hours ago
verdverm | a day ago
I would imagine they all converge on common features and core implementation foundation
[OP] IvanK_net | 23 hours ago
verdverm | 23 hours ago
This day in age, we need to verify ourselves
Can you show us an example? How did you verify?
sampullman | 17 hours ago
verdverm | 17 hours ago
I would think a github link would be easy to provide, sus that it hasn't been
Mashimo | 12 hours ago
verdverm | 8 hours ago
This smells a lot like the Laya thing to me, especially with the astroturfing by friends and fans
Mashimo | 4 hours ago
[OP] IvanK_net | 15 hours ago
I wanted to discuss the behaviour of Github without giving these "projects" even more attention.
ChrisRR | 13 hours ago
Because if the javascript source matches the source in the repo, then they copied it
verdverm | 8 hours ago
aetherspawn | a day ago
If you have one of these, it’s possible that GitHub would honour it if you go via a lawyer.
JohnFen | a day ago
As an aside, I thought that "cracked" software meant software that has had the copy protection or other access control bypassed or removed, not the alteration of the software functionality itself. If your software was actually cracked then you may have some fairly heavy law in your favor. For better or worse, bypassing access controls (even weak or simple access controls) gets special legal attention.
y-curious | 17 hours ago
Onavo | 17 hours ago
janalsncm | 17 hours ago
msdz | 16 hours ago
pluc | 12 hours ago
jasode | 12 hours ago
Less than 7 figures (~1 million) per year -- not per month -- based on previous comment from 2021: https://news.ycombinator.com/item?id=26769141
A later 2023 interview updated it to ~$200k/month (~2.4 million/year) : https://web.archive.org/web/20240606073354/https://saastrapp...
fg137 | 11 hours ago
(I'd just quit my job if I had an income like this.)
schnebbau | 11 hours ago
janalsncm | 17 hours ago
Shank | 16 hours ago
Scaled | 12 hours ago
mistrial9 | 23 hours ago
My reply is that you now own a customer list, brandname and trademark, and that is about it.
lrvick | 22 hours ago
I would not fork or re-release proprietary code. I would ask my LLM to write a very rigorous end to end test suite for your tool, delete all the code, then have a clean context LLM re-write the code to pass all the same tests. Then I could publish it under an open license.
Ads are a cancer, and it is a matter of weeks before someone does the above where you have zero recourse.
I suggest open sourcing the code properly without ads yourself before someone does it for you. If you do that someone might donate to you instead of paying for the tokens to clone your work.
Software is no longer a moat and DMCA means nothing anymore.
lofaszvanitt | 22 hours ago
Madmallard | 22 hours ago
lrvick | 22 hours ago
The real engineering work that will always be paid for is identifying problems and testing solutions to see what solves the problems.
The substrate in which we use to do that will change, but the job will endure.
Those that just do what they are told however, yeah they are SOL unfortunately.
Creative problem solving is the only skill that will matter anymore.
lofaszvanitt | 22 hours ago
lrvick | 21 hours ago
If security is a solved problem then anyone that wants to teach themselves enough can move to trying to solve disease, until disease is solved, then we all move on to building enough robots to mass produce enough food to solve world hunger and shelter... and once the needs of everyone on earth are solved at an ever cheaper price until it is free... then I guess we do whatever we want.
ipaddr | 16 hours ago
Madmallard | 14 hours ago
lrvick | 4 hours ago
I feel like trying to better humanity, even if I fail, is a better use of my time than simply saying nothing can be better and giving up. At least by failing well, at worst, the next delusional person can carry the work forward learning from my mistakes.
It is going to be a slog, likely over multiple generations, but one worth the climb.
Madmallard | an hour ago
If you have the capacity to do that, I.E. a multimillionaire, then sure.
lrvick | 12 hours ago
Capitalism is just a bootloader to get us there.
bluefirebrand | 11 hours ago
lrvick | 6 hours ago
Humans once built things to benefit society over multiple lifespans.
MentalM | 6 hours ago
lrvick | 4 hours ago
MentalM | 10 minutes ago
That is not the things that can be unlimited. There will always be better food, bigger houses, better medicine etc.
In the eyes of the bottom 30 (or maybe even 60) percent of humans on the planet Earth average American already has the access to unlimited food, shelter, medicine, and knowledge. But good luck to convince Americans that they have those access.
Madmallard | 18 hours ago
It's not. The economic landscape is also entirely different from before as well.
lrvick | 12 hours ago
Madmallard | an hour ago
Doubtful when stock prices go up because companies lay off/fire employees.
Doubtful when hiring foreign workers for cheap is strongly preferred over their own citizens.
If you're already a millionaire now invested in tech and S&P500 and have property maybe you'll be alright and maybe you won't agree with this perspective, but my perspective applies to the vast majority of people.
lrvick | 22 hours ago
verdverm | 22 hours ago
saaaaaam | 17 hours ago
prmoustache | 12 hours ago
If ad was the only way to get money, there would be no product/service to sell anymore and thus...nothing to advertise. It just cannot work that way.
fg137 | 11 hours ago
Photopea is lucky that it has a decent amount of revenue. But that's an exception, not the norm. Generally speaking, for new software, the business model of desktop, client-only software hasn't worked well since late 2010s at least, and nobody should expect to run a viable business like that today. There are very few applications you "install" on your computer that doesn't require native capabilities in some way.
kqp | 17 hours ago
lrvick | 12 hours ago
klntsky | 17 hours ago
fg137 | 11 hours ago
A closed source, client-only "desktop" application, especially a web app with obfuscated/minimized JavaScript code, has no real copyright protection these days. You either sell ads, sell it to enterprises, or if you are lucky enough to be able to pull it off, sell a subscription. Not putting the logic on the server in the first place means everything is basically public knowledge.
penskymaterial | 22 hours ago
If you want to make proprietary software that's cool, but client-side JavaScript was a terrible choice. The cat is out of the bag.
There's a reason software for which you purchase a license key generally doesn't give you source code outside rock-solid legal agreements.
jffry | 22 hours ago
penskymaterial | 22 hours ago
Because what I see is essentially "they're storing stolen property" but the burden of proof is on the author to prove it was, indeed, stolen.
I imagine the bar for that is pretty high otherwise anyone could weaponize DMCA to target their competitors' repositories.
jffry | 22 hours ago
That's not what OP alleges - they are saying people are redistributing modified versions of OP's copyrighted code. DMCA is an appropriate measure in such a situation, but it's unclear why OP's DMCA takedown was rejected by GitHub. Without more detail, it's hard to comment further
verdverm | 22 hours ago
majorchord | 18 hours ago
https://reclaimthenet.org/kiwi-farms-dmca-subpoena-anonymous...
bartread | 22 hours ago
That is an extremely disingenuous and bad faith interpretation of what OP has said and I think you know it. You want to be edgy? Go comment on Reddit.
OP is rightly frustrated that their copyrighted work, that they’ve been working on full time for over a decade, is simply being ripped off by people and GitHub refuses to do anything about it.
penskymaterial | 22 hours ago
Shifting blame to GitHub is absolutely idiotic.
Try removing locks from your doors in a high crime area (which is what the Internet is) then being indignant when the police can't stop all the criminals stealing your property.
cbarnes99 | 20 hours ago
fg137 | 11 hours ago
ChrisRR | 13 hours ago
ryanascend | 5 hours ago
samatman | 3 hours ago
This is a good faith contribution to the discussion, and frankly, the way things are going, the point it raises is something most of us need to consider.
binlog | 22 hours ago
jdlshore | 22 hours ago
bartread | 22 hours ago
OP, I’m sorry this is happening to you. It must be incredibly frustrating to have people ripping off something you’ve worked on for many years and pass it off as their own work. I would be furious in your position.
I wish I could do something directly to help you but the best I can offer is to echo the best advice others have already given you: it’s time to get a lawyer. That is the one guaranteed route to get GitHub to sit up and take the action they should already have taken on your behalf.
handoflixue | 22 hours ago
Right now, the settled law is that such an LLM reproduction is 100% legal.
If you really want to protect your software in the years to come, you might have to seriously consider starting some sort of popular political movement to address this issue in copyright law.
Current models can already do a full reproduction of anything with source code available (e.g. JavaScript...), and there's already been some poor-quality Photoshop knockoffs.
tgma | 22 hours ago
Or perhaps the people should admit that copyright, an artificial construct which is not rooted in natural property, was inherently broken and is not (or at least no longer is) a net benefit to the society and simply adapt around it.
theturtletalks | 22 hours ago
I’m personally waiting for LLMs to get so good that I can make music and movies based on my favorite ones. I probably could never release it to the public, but being able to make it and enjoy it myself would be amazing.
verdverm | 22 hours ago
I have agents maintaining several patches to my main tools, not forking, not sharing (some have no interest), personal adjustments
tancop | 15 hours ago
There is basically zero pushback to generated code. All the crazy Minecraft in GTA type mods that came out in the last couple weeks are obviously vibe coded but no one cares because they play good and surprisingly bug free.
If he put in AI visuals as in generated textures then it's different, because that's way more visible and gets labeled as slop immediately. There's also the (accurate imo) perception that AI is taking artists jobs against their will but coders adopted it on their own and benefit from it, so using it for code is ethical from a labor rights POV.
verdverm | 8 hours ago
tgma | 21 hours ago
Modifying/modding/remixing software was simply not as feasible as music, but LLMs made it possible.
mschuster91 | 15 hours ago
Copyright, patents and IP are the evolution of our (Western) way of converting research into a form of financial investment.
ButlerianJihad | 15 hours ago
And a big church could employ lots of them, and thereby stimulate the economy. It seems that the Baroque Era and churches crammed to the rafters with art, may be an artifact of a very good job market for those architects, craftsmen and artists!
Yeah... you could copy some sheet music and share it around, but it still required skilled musicians to perform, play and sing it. And nobody was taking photos or uploading JPEGs of your art and sculpture, so it was fairly locked-in that people needed to visit, and see it in context. So it stood to reason that you could probably reconstruct Noah's Ark from the fragments of True Cross that were circulating around Europe... and how many fingers did your favorite saint really have?
Copyright-free church economics have sort of fallen apart since then. However, museums, arena concerts, theaters and the rest, they have all taken pages from the Church playbooks. The fact that a church can still draw in hundreds for a show with great production values, every week or daily, seems dull and unremarkable now, but a good rock concert or museum collection can evoke the same "goin' to church" fervor in people who like that kind of stuff.
account42 | 14 hours ago
CamperBob2 | 6 hours ago
Won't work this year, but it probably will next year. Copyright is done.
handoflixue | an hour ago
That said, I mostly end up using open source for the same reason
14u2c | 22 hours ago
How so? Interfaces are not copyrightable, but that it not the same as dissecting a js bundle and copying the implementations. Are we sure these LLM are keeping sanitary habits there?
verdverm | 22 hours ago
several courts have ruled Ai output is not copyrightable, I am unaware of any co-authored cases
abrookewood | 22 hours ago
verdverm | 22 hours ago
kube-system | 16 hours ago
But, the use of LLMs is not disqualifying. To qualify for copyright protection your work simply must have a sufficient degree of human authorship.
However this is just about protection, not infringement.
If you use an LLM to generate something and that LLM just happens to output something that another human wrote, you may be liable for copyright infringement.
fg137 | 11 hours ago
kube-system | 6 hours ago
https://www.jonesday.com/en/insights/2025/02/copyrightabilit...
nathanlied | 22 hours ago
handoflixue | an hour ago
I'm not convinced we are actually at the point where something like Photoshop is trivial to rebuild. That involves a lot of manual QA and the expertise in actually knowing how everything should work.
That said, give it 6-12 months and I won't be surprised if they can one-shot "create a future-complete clone of Photoshop, make no mistakes"
kube-system | 16 hours ago
Where did you hear that? Because it is 100% untrue and is the opposite of current legal guidance from reputable legal expert
handoflixue | an hour ago
The current fun loophole is to have the LLM decompile the existing code, build unit tests around that, and then have a different LLM model build the code that satisfies those tests.
Either way, you can absolutely get a "clean room" result from an LLM.
codingdave | 2 hours ago
My understanding was that re-invention without copying any code is legal. But scraping code from the browser and re-using it is not. I'd love to know how that plays in the courts with LLMs, as their entire model comes from copying code as training material, not writing new code from scratch.
handoflixue | an hour ago
Regular humans train on copying code too (Stack Overflow, etc.) so unless they were trained on that specific codebase, I really doubt you have any sort of legal standing. And given how little compensation the authors got when their work got trained on, I wouldn't hold out hope for a big payout even then...
ranger_danger | 22 hours ago
Sorry GitHub, that's not for you to determine, as you are not a US judge. They should never have replied like this IMO and this behavior opens them up to liability for not properly handling DMCA procedures.
Proper DMCA 512(h) notices (assuming OP's was proper) require the host (github) to remove or disable the content first without even attempting to verify the claims.
Then the repo owner has a chance to challenge the notice. If they choose to do, they're basically required to publicly doxx themselves first, by nature of just going through the motions of the judicial court system.
If there was no challenge after a set period of time, then the content stays down.
If there was a challenge, it stays down until a court decides what happens next.
verdverm | 22 hours ago
two sides to the coin, we'll hear about how some evil corporation used their influence to have a legitimate project DMCA'd and HN will have the opposite reaction on that day
something like "jury duty" from the community seems an interesting idea for a middle path, if we want better systems, we'll all need to contribute a little to making it so
ranger_danger | 17 hours ago
samatman | 3 hours ago
What happened here?
ranger_danger | 32 minutes ago
But 1201 deals with circumventing copyright protections and AFAIK isn't related to DMCA takedowns, but 512(h) is what I've seen typically used for DMCA notices instead, to get the identity of a poster in order to sue them (since the ISP itself is exempt as a conduit), so that's why I mentioned what's required for it.
jameshilliard | 22 hours ago
Did they actually republish you code or were they just creating wrappers that download/cache the code from your website to run locally?
busymom0 | 21 hours ago
ChrisArchitect | 20 hours ago
Photopea creator weighs in on Photosuite project
https://news.ycombinator.com/item?id=49972730
anilgulecha | 18 hours ago
You had commented on the photocraft post prior, so if it's that, then it's a bit muddled. It's a LLM based re-implementation and not a copy of the code made open. So the argument would be weaker there, and you'd really need specific code samples to make a case of copyright infringement. Photocraft not "piracy" as is normally understood, which is the exact same binary, optionally with the license protection removed.
thought-gap | 18 hours ago
Second, I am sorry this is happening to you.
Third, based on GitHub's reply, specifically
> we're unable to confirm a violation of 17 U.S. Code § 1201
they took your submission as 17 U.S. Code § 1201 takedown notice. Maybe you specifically stated this. Maybe it was implied. This is likely not what you want and GitHub's response is likely correct. The reason for this is that § 1201 prohibits circumventing a technological measure. The JS you host on your public site, even if obfuscated, very likely does not qualify for this protection. Another detail - the reason it took long (a month later according to your post) is that after the youtube-dl fiasco, they committed to manual review, legal and technical, of every 1201 takedown notice [0].
Fourth, if you believe these copies are sufficiently reproducing your copyrighted work, what you likely want to do is file a standard copyright infringement 17 U.S Code § 512(c) takedown notice. This still goes through the same DMCA report flow but it should result in a less stringent review process and a faster response.
Fifth and finally, consider asking your favorite LLM to get more context around these laws. Good luck!
[0] https://github.blog/news-insights/policy-news-and-insights/s...
apefulsin | 8 hours ago
eli | 8 hours ago
1201(a)(3): "As used in this subsection-- to 'circumvent a technological measure' means to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure, without the authority of the copyright owner"
darkwater | 7 hours ago
eli | 7 hours ago
Maxatar | 4 hours ago
eli | 2 hours ago
keeda | 5 hours ago
cute_boi | 5 hours ago
eli | 2 hours ago
tothrowaway | 7 hours ago
kasajian | 17 hours ago
anon48293 | 16 hours ago
So you are going to have to prove their code is a copy of yours, not just a copy of the functionality.
In Google vs Oracle, APIs also aren’t necessarily copyright able:
“So long as the specific code used to implement a method is different, anyone is free under the Copyright Act to write his or her own code to carry out exactly the same function or specification of any methods used in the Java API. It does not matter that the declaration or method header lines are identical”
To sum it up; get a lawyer.
BSVogler | 16 hours ago
GoblinSlayer | 13 hours ago
Razengan | 15 hours ago
Meanwhile AI refuses to touch photos that contain anything that remotely looks like Mickey Mouse.
Shit was never on the Common Folk's side.
fuzzfactor | 12 hours ago
This doesn't lend it self to a sensible solution.
There's no way that computer code should have ever had any legal similarity to entertainment properties like Disney characters.
Plus so many people don't want to pay any attention to the way there's a big difference between entertaining software like games versus things which are needed before "machines" will even (barely?) run, or run more superbly which is not the same either.
And there's no way any "rights" should exist for an extended period.
Among other things these need to be corrected more so than ever (or AI will do it for us). The problem is it all needs to be sensibly reversed not gutted in one big shockwave. But AI is here to shock. It doesn't even take superintelligence, if the people who gradually caused the problem over the decades were below-average things would have come out better as long as their objectives were less predatory.
[OP] IvanK_net | 15 hours ago
Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.
I think I will try solving it with a lawyer. But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.
brnt | 15 hours ago
I think anybody in any line of work or life would like that. It's however unlikely to never run into an issue where a lawyer is really needed, so don't hesitate when you realize you need one.
ChrisMarshallNY | 11 hours ago
https://youtu.be/jVkLVRt6c1U
Qwuke | 11 hours ago
graemep | 9 hours ago
gpugreg | 9 hours ago
graemep | 8 hours ago
The US allows damages per infringement without need to prove an actual loss, and per infringement.
dannyw | 7 hours ago
In my experience GH usually does 512(c) takedowns in days; so it taking a month is quite abnormal. OP’s posted response suggests he didn’t file a copyright takedown but rather an anti-circumvention claim; which is a bit special in DMCA law, and generally best avoided when you have merits to do a regular 512(c).
We also don’t have details of the repo. The author has commented on another project that claims to be a LLM _re-implementation_ of Photopea, without directly using source. If that’s the case, it’s entirely understandable why GitHub won’t take it down.
zdragnar | 7 hours ago
kevin42 | 7 hours ago
I spent $18k in legal fees over a $22k claim in a construction dispute. I won the suit and was awarded legal fees. So I'm owed $40k plus interest. I've collected exactly $0. The last lawyer I spoke to said I need to cut my losses in legal fees at some point because from a practical standpoint, winning damages isn't the same as collecting them. Especially if the defendant isn't local and has few assets.
hermitcrab | 9 hours ago
It worked for me! And very quickly.
https://news.ycombinator.com/item?id=49832406
But it is a bit crap that this is the only way you can get Github to behave responsibly.
Good luck.
Kivan_net | 15 hours ago
randyrand | 14 hours ago
SeriousM | 14 hours ago
RobotToaster | 14 hours ago
Mashimo | 12 hours ago
pbasista | 14 hours ago
> take the Javascript code from my website, remove all ads from it
I would assume that this might be one of the reasons why people are modifying and repackaging your product. I would suggest to remove that incentive. So that the people will have no reason to repackage your product because it has annoying features. And so that they could use it directly and be happy about it.
boxed | 14 hours ago
1718627440 | 13 hours ago
pbasista | 12 hours ago
No one implied that the author should offer their product for free. I merely suggested that they need to focus on other aspect of their product rather than the mechanical software parts because they can no longer be the differentiating factor. Precisely because they could easily be recreated or copied.
boxed | 5 hours ago
fg137 | 11 hours ago
I say that as someone who thinks about this almost every day.
robotmay | 13 hours ago
pbasista | 13 hours ago
I think that the differentiating factor must be something else than the software product feature. Because that can easily be copied or recreated.
It can be e.g. the customer support where customers will be listened to and will have their suggestions and requests implemented as features.
fg137 | 11 hours ago
Arguably Photopea made a mistake, and now they are paying for it.
They can fight, but it's a losing battle.
AlienRobot | 11 hours ago
Do you have any concrete ideas for how to do this or are you just saying this to defend piracy?
jakub_g | 14 hours ago
https://github.com/martinwoodward
before starting heavy artillery with lawyers.
(Martin also often posts on HN).
sourcecodeplz | 13 hours ago
Wonder how many even built a popular free product supported by ads?
It's quite difficult and you need to provide even more value than a paid product (if that makes sense) for users to come back constantly.
There is nothing new now with people copying software. It's just that much MORE of the masses have access to this now than before.
And thus thieves multiply exponentially.
schnebbau | 13 hours ago
I think we're also going to see the strategy to be to remove the processing and magic sauce from the client and move it to the server where it can't be decompiled and rebuilt with AI.
lesspassiveobse | 13 hours ago
ChrisRR | 13 hours ago
schnebbau | 13 hours ago
Also if it could recreate it that would be fine, because it would be doing so without having access to the source.
pixl97 | 10 hours ago
This doesn't sound that hard to automate these days.
alpaca128 | 10 hours ago
I find it unlikely that photopea was never scraped for AI training considering they are looking so hard for new material they started buying up and scanning old books.
1718627440 | 13 hours ago
TeMPOraL | 13 hours ago
SaaS killed Open Source with it, two decades ago.
anakaine | 12 hours ago
I'd wager we will start to see more web apps like this have greater obfuscation and dependencies on operating on a particular domain. Sure AI can help to circumvent many things, but at a certain point they pay-off may not be worth the effort.
fg137 | 11 hours ago
The magic sauce haven't been in the client for many applications for years. Google barely has any application that runs on desktop OS even though they could have released them.
jasode | 10 hours ago
It's a 1-man operation so it may have not have been financially viable to architect the app as server-based.
- server-based : must invest a lot more money in server farms and extra disk storage, or pay high AWS cloud fees. E.g. if a million users do a blur or denoise filter, all that cpu processing has to happen on the servers, and massive disk space to hold the intermediate files, and extra bandwidth costs to send the changed bytes back to the client.
- client-based : just ship Javascript blobs to end users' web browsers because the blur/denoise/etc filters happen on the desktop.
Also, this type of pixel-editing software still needs a ton of client-side Javascript to behave like a Photoshop clone because users want to see interactive changes as they dynamically slide the blur/noise/etc settings. Round-tripping that with extra server latency is not a fluid UI experience.
We can't confidently replay the past and say that starting it as server-side app from the very beginning means he'd have the same $million in revenue today. Instead, the extra server costs and UI jankiness could have doomed the project.
fg137 | 9 hours ago
It's a business decision, and I'm not sure if they made the right decision. Most client-only web applications are open source because they know there is no business in selling it as a service. Photopea somehow is an exception, but its business model is getting questionable which is not a surprise at all.
It's also possible to use a combination of cloud based and local computation. Figma is doing quite well in that regard, especially with the use of WebAssembly. No doubt that potentially means more work, and potentially forcing users to create account etc. But hey, that's a business decision as well. If you don't do anything but just keep everything in JavaScript, this was going to happen.
flomo | 3 hours ago
Server-based photoshop clone sounds more like VNC/RDP, for this sort of thing client processing is a better UX.
pluc | 13 hours ago
summarity | 13 hours ago
As for DMCA filings, we publish all of them here: https://github.com/github/dmca
I see two from Photopea, one from 2022 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) and one from 2024 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) - could you point to the recent filing?
I work at GH, but am not involved in DMCA filings, and can in no way answer or judge this case, but potentially follow up internally.
[OP] IvanK_net | 13 hours ago
Github did take down this https://github.com/spooknik/Photopea-Appimage and other repos in the past, but now, I feel like I talk to a robot. I am happy to hear that they have real employee! :D
anilakar | 13 hours ago
philipwhiuk | 13 hours ago
(I only noticed because your site is not blocked in the UK but most of the templates are.)
msalihb | 13 hours ago
sen | 12 hours ago
2b3a51 | 12 hours ago
Best of luck with the copyright complaint.
throwawayffffas | 13 hours ago
Hire a copyright lawyer.
Start going after the people that run this as a service, for both copyright and trademark infringement (you have a trademark for photopea right?).
nchmy | 12 hours ago
anonym29 | 11 hours ago
This reminds me of LLM companies scraping the entire internet and destroying millions of books to scan them in bulk quickly and then complaining about others performing distillation attacks against their models.
It's fine to be unhappy about people coming to you with complaints about forks of your software, but if the premise of your project is "we made a near perfect clone of Photoshop so you don't have to pay for it", haven't you kinda ethically ceded the right to complain about other people copying your software, even if you managed to stay within the confines of copyright law?
If you're building on other people's ideas and work, don't you owe the world a duty of reciprocity in openness?
bitwize | 10 hours ago
Bring back look-and-feel copyrights and the Whelan interpretation of software copyright. Programmers have gotten away with stealing the patterns for entire programs, producing identical clones of another company's valuable IP, for far too long.
I have a feeling that Whelan is going to become relevant again as judges realize that people are using AI to copyright-launder major applications and games (a practice for which I'll coin the term "sloppylefting"), effectively stealing them in a way that cannot be prosecuted using the current very strict interpretation of copyright law with respect to software.
MisterMunchkin | 11 hours ago
lewelove | 10 hours ago
Someone can always make a new repo without redistributing your code, sourcing and hot-patching it directly from your domain. GitHub deleting this repo won't ever fix it, you're playing whack-a-mole and doing free PR for these repos here on HN.
We seem to forget that this website is called Hacker News.
fn-mote | 10 hours ago
I do not want enshittified software that creates a bogus need for a server in order to extract licensing fees from me. I prefer to pay for locally run software, paying in ad views if I have to because that’s the micropayment system we have ended up with.
So is there a path to an ethical, viable business model for the author?
gewetensleegte | 10 hours ago
.. is something the author should have considered before deciding to publish AdWare.
RugnirViking | 10 hours ago
Adverts are likely a poor business model here - if you want to sell to professionals and creatives, the visual look of the software matters. It should really be subscription or one time licence
ang_cire | 10 hours ago
The old model of server-locked licensed software is going the way of the dodo pretty fast right now, though people may not realize it if they're not hunting for alternatives to the old guard suites yet.
And while personally I agree with the commenter above you for personal reasons, I also think that the OP is missing that while the people who've ripped their js tool may have done so directly from their site, no one certainly has to any more: they can likely black-box something similar pretty quickly, at which point the author's DMCA moat is gone.
lewelove | 9 hours ago
Yes and no. An ethical business model for software in this world must be built on a long process of collecting good faith from customers, it just doesn't pay well enough compared to the ones that shatter said faith (adware, exploitation, dark patterns). I think the software moat will be more and more based on social capital. People are happy to pay for the software if they know for a fact that company/person behind it isn't being hostile to them. Look at Steam as an example of this. And you can always open source your code, and still make money through the means of good faith. Is it actually viable? I don't know. It depends on how much money you want to make.
prepend | 9 hours ago
Stopping me from editing out parts I don’t want to run seems odd. If you want me to run certain things, do it on your own hardware.
This reminds me of the arguments against ad blockers. I don’t want people to force me to watch ads and not allow me to block them on my own machine.
criley2 | 9 hours ago
From my perspective, those people who are taking this public client side code (not emulating any kind of server), and removing the privacy nightmare, are actually doing good for society. The software is more usable, more performant, and far more secure when they are done. The only harm is the authors ability to monetize.
I don't think it's possible to have a fully client-side web product and be able to enforce strict guardrails on the use of the code. Regardless of ethics, it's just not feasible. What you give up by delivering the full source code to the browser to render is control over the source code.
If the author wants more control over their source code, and easier monetization, they should compile a binary and distribute that. The guardrails protecting source code, duplication, and copyright infringement are much more clear. That's just the harsh reality of delivering source code to clients.
limagnolia | 9 hours ago
That is my preffered business mkdel for software development.
p-e-w | 9 hours ago
That may well be, but as long as that concept exists in law, I sure would like every developer to be able to benefit from it equally, not just Microsoft and Adobe.
Roark66 | 9 hours ago
At the end of the day the fact many people abuse IP laws doesn't mean there are no legitimate uses.
epihelix | 7 hours ago
Why is it comedic? All of my own code is open source and freely available, but protected by copyright -- namely via the GPL. Copyright is what helps ensure that we retain open code, and ensures that it propagates openly.
How much further along the enshitification path do you think Android would be, if Google wasn't bound by the GPL in so many areas? Copyright with code is not only fair (why on earth would creating code be different to creating anything else?) but it is what keeps so many things free and open.
samatman | 4 hours ago
Guess we'll never know.
zelphirkalt | 2 hours ago
prologic | 10 hours ago
cpach | 9 hours ago
kiririn | 10 hours ago
*They wash their hands of any GDPR deletion/anonymisation requests, instead passing them and your identity documents to the repository owner!
cringleycringe | 9 hours ago
DannyBee | 9 hours ago
1. Pay a lawyer or firm that specializes in this sort of thing to play whack a mole for you
2. Accept it as normal losses and ignore it.
Contrary to others claims here, it is not a 500/hour thing to do #1 when dealing with firms that specialize in this. it probably would be if you just hire a random one-off IP lawyer to try and deal with this particular instance.
Trying to deal with it yourself will be increasingly frustrating and time wasting for you. You will also never be able to prevent someone sufficiently motivated from doing stuff like this to your software.
Unless you want to spend your time dealing with those folks instead of building the software, you should hand this part off - it's not a good use of your time, value wise.
Put another way: most companies farm out processing of this sort of request to high volume low cost processing teams. Or AI. Or both. For you this is an important one off. For the person processing it it's one of a hundred tickets they are handling today. You are not going to get very personalized attention and consistency.
I don't claim this is how it should be, etc. I simply claim this is how it realistically is. It would practically require legislative change to have a different thing happen here and while interesting to discuss, that seems outside the scope of your questions, which seemed more practically oriented
monster_truck | 8 hours ago
ktm5j | 8 hours ago
DannyBee | 7 hours ago
As a general rule, you can write off what it costs for you to make something, but not what you lose from not being able to sell it.
Which means for physical goods, you write off the cost to make them, and for digital goods, you can similarly usually deduct development cost to make the software.
In neither case can you write off the amount you would have made had it not been stolen/sale had not been lost.
The practical effect is that because physical goods have a per-unit to-make cost, and most digital goods don't, physical goods get written off per-unit-lost and digital goods do not.
At least, this is the most general answer I can give you for that level of general question.
plumbees | 7 hours ago
thenewnewguy | 6 hours ago
To write something off you have to actually lose the money - writing off is a process to decrease your taxable income by your expenses, unless you're inventing fake expenses (read: performing tax fraud) it doesn't generate a greater amount of money than the expenses.
voakbasda | 7 hours ago
The bad guys are winning, because the good guys have no legal recourse. The only practical solution is vigilante justice, but that makes you a bad guy.
In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice?
cassonmars | 7 hours ago
keybored | 7 hours ago
throwaway27448 | 7 hours ago
DannyBee | 6 hours ago
Civil law systems largely aren't about "good" or "bad". Justice there isn't "good guys win" and "bad guys fail". It never has been.
It's about trying to reasonably resolve disputes. That's all. Civil legal systems were created not to enforce morality or social order, but instead to formally resolve disputes. The system is pretty good at doing that. It will never resolve all disputes, let alone resolve all disputes in an "optimal" way (for any possible definition of optimal you come up with). It only tries to do a reasonable job of it.
If your expectation is that the law will stop "bad" actors from acting "badly", i think your expectations are out of whack. Yes it gets tried, but it is a fairly miniscule portion of the system overall, and generally not a very successful part of it. It's also remarkably recent in the history of legal systems. It is a quasi-political thing that the legal system simply isn't good at dealing with, and really is not a good match for it. I think results bear that out so far
You can take that for whatever you want - I can only tell you why the system is there, historically and currently. That doesn't mean you have to like that idea, and you are welcome to rail against it.
45sdasf45 | 6 hours ago
The Justice is the liberation of code from those that wish to seek rent from it.
mschuster91 | 5 hours ago
Guess why trust in democracy itself is eroding everywhere and why even executing a health insurance CEO on broad daylight is not just widely approved but widely beloved.
The rich can get away with anything (Trump's claim of "I could shoot someone on 5th ave and get away" is pretty realistic, to say nothing about the Epstein crap), but if you are poor or, even worse, an immigrant - pray to God to help you because not just will no one else help you, but in the worst case you might end up getting fucked over for seeking help.
initatus | 2 hours ago
An Axios poll showed 17% found the murder "acceptable" or "somewhat acceptable." Curious where you are seeing such wildly different numbers?
https://www.axios.com/2024/12/17/united-healthcare-ceo-killi...
bsoqk | 4 hours ago
blahyawnblah | 4 hours ago
cpach | 3 hours ago
tim333 | 6 hours ago
keeda | 5 hours ago
Are patents the only real IP protection left for software?
And would a patent (assuming this application had something patent-worthy to claim) help at all here? As in, in addition to sending a C&D maybe also including language about patent infringement would be more effective?
I know that patents are unpopular for many here (including you, IIRC!) but I think this question is extremely important, especially to anyone who wants to make a living purely off the software alone.
Remember: if no other moats or business models or funding models lend themselves naturally to the software in question, anything bolted on is pretty much already on the slippery slope to enshittification. A mechanism that encouraged people to compensate fairly for the value provided by software would be better for the Internet than what we've got going on today.
nradov | 4 hours ago
modzu | 3 hours ago
keeda | 28 minutes ago
But as sibling comment indicates, even that is no longer a guarantee. There are demonstrations and anecdotal accounts of reverse engineering entire features or even small applications, including the backend code, by pointing an LLM at the web UI: https://www.thoughtworks.com/insights/blog/generative-ai/bla...
This is why I'm thinking that patents and other legal means are likely the only way forward to protect software that does not have a natural moat, like network effects or some huge data advantage. That is actually a huge amount of software.
My concern is that without proper protection software without such moats, this will create incentives for people building them to adopt less-than-ideal means of monetizing their work, e.g. the things that lead to enshittification.
kittikitti | 3 hours ago
cpach | 3 hours ago
kittikitti | 2 hours ago
cpach | 2 hours ago
bityard | 9 hours ago
pdutt111 | 9 hours ago
onlyrealcuzzo | 9 hours ago
Can't you just steal the entire WASM code just as easily? I mean, I guess if the ads are stuffed in WASM that becomes a problem. But LLMs are pretty good at reverse engineering. I can't imagine it would be too much effort to get them to take the ads out, or to replace your ads with their ads.
gpugreg | 8 hours ago
ShinyLeftPad | 9 hours ago
gwbas1c | 8 hours ago
Remember that there is still quite a bit of friction to doing that, and that many people have better things to do than jump through those hoops.
In addition to the "hire a lawyer" comments in this thread, I suggest building in some heuristics that detect when Photopea is running outside of your domain. They don't need to be "foolproof," but add additional friction to pirating Photopea so that less people will jump through the hoops.
Some historical examples:
- Commercial software in the 1980s and 1990s would burn a hole on the disk, and the software would look for the error when reading that sector.
- Donkey Kong Country would detect that it was pirated by reading the amount of RAM available. (Because SNES backup systems had slightly different runtime properties than the real cartridge.)
More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.
---
Finally, you could consider a business model that relies on server-side functionality for revenue or stickiness, that's hard to replicate merely by pirating the software. (IE, some kind of server-side storage and sharing system.)
svantana | 8 hours ago
If they're using the github.io repo, the web app can be just as accessible as any other site
abcd_f | 7 hours ago
This is a very frequently repeated point, which is invalid.
Crashing pirated versions do not affect the reputation of the original. It’s an urban legend.
People using pirated versions are perfectly aware of the fact that they are using butchered versions of the original. So when it crashes, chances are it's because of a botched DRM bypass. It's an obvious connection, has always been.
ravenstine | 7 hours ago
Today, there is little point in trying to slow down software pirates. At best, adding an arbitrary piracy detection only adds anywhere between mere minutes and a few days to the effort to crack software. This is true absent AI assistance or even a meaningful understanding of ASM outside of logical JMP instructions. The author will likely waste more of their time implementing anti-piracy techniques than a software pirate would figuring out which function call results in the program exiting abruptly. I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities. This is in spite of various licensing and contextual checks throughout.
It would slow down a pirate more to have a program modify or decompress itself in memory, but that class of techniques is still more trouble than it's worth. Experienced pirates already know how to deal with those traps. The timeout thing you mentioned is clever, but the type of person who knows enough to disassemble software would think to themselves "wtf does it crash after 5 minutes?", immediately investigate, and identify the source of the crash.
Having a license check is the only thing authors of software should bother with. It provides most people a framework to consider whether they should pay for a product. Most people won't download potential malware from a sketchy website if you offer your product at a fair price. Those who either know how to crack apps or refuse to pay will keep doing what they're doing.
tl;dr Don't fool yourselves into thinking you'll outsmart a kid with Ghidra installed by throwing a glorified if-statement in their path.
EDIT: I'm speaking in the general sense. The same principles apply to an app that runs almost all of its logic in the browser.
eps | 6 hours ago
There are some, with code consistency cross-checks and such. Cracking them with static code patching can get very time-consuming. Patching them dynamically works, but some have checks for that too. It's not common though for sure.
ravenstine | 3 hours ago
Timon3 | 3 hours ago
SleepyMyroslav | 3 hours ago
WhereIsTheTruth | 8 hours ago
conartist6 | 8 hours ago
It won't stop AI thieves cold, but now they'll be in violation of two kinds of law unless they do a bunch more work to rip out all the trademarked branding.
Finally, move beyond ads as your business model.
An ad blocker removes the ads from your website, and still leaves you paying to host the traffic. In a way it's worse for you than what unauthorized mirrors are doing. You're seeing that there's unmet demand for what you are offering, so my advice is: figure out how to capture that demand. Why aren't those people taking the deals you're offering them?
I took the liberty of disabling my own ad blocker to do a little research and HOLY COW THESE ARE BAD ADS.
Let's lay out the problems:
- Something is horribly mangled in the ad loading code. The ads flash in and out of existence, and cycle through at breakneck speed, ~5 seconds per ad. Between the flashing in and out and the flashing different ads, it is not possible to do serious work with this going on.
- Many of the people who don't have a photo editor on their device are using touchscreen devices. Many of those people are right handed. For them the actual photo editing tools would be largely impossible to use without accidentally clicking a giant ad which takes up the whole right side of the screen, at which point they would no longer be able to edit photos. Once this happens to you 5 times or so I imagine you start to get very angry.
- Because the ad doesn't fit into the UI at all, you're wasting huge amounts of the screen and impacting productivity proportionately.
So I guess my final advice is: if you don't respect your users, I don't know why you would expect them to respect you. Offer a better deal and more people will take it.
conartist6 | 8 hours ago
jodrellblank | 8 hours ago
fishgoesblub | 8 hours ago
TheSkyHasEyes | 7 hours ago
MiloLeo | 6 hours ago
thraway3837 | 4 hours ago
-Another indie developer who hopes to have 1/100th the success that Photopea has had.
AbuAssar | 8 hours ago
hereme888 | 7 hours ago
Look at Adobe Photoshop was just ripped as a clean, open sourced project:
https://x.com/esrtweet/status/2107561430568571363
hgs3 | 6 hours ago
> Do you think I should look for a lawyer to deal with it outside the digital world?
Absolutely. This is a copyright infringement case and there is now an appellate precedent to cite. Gather as much evidence as you can and speak with an IP attorney.
[1] https://www.reuters.com/legal/litigation/unsealed-opinion-sh...
hungryhobbit | 6 hours ago
... so virtually no one considers that ruling to be the final word on the topic (sadly).
alightsoul | 5 hours ago
I don't think it's enforceable or even applicable here. "The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content "
this comment is misleading.
keeda | 5 hours ago
Also TFA is about a much narrower ruling than it first seems:
>The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content — and the appeals court said in a footnote that concerns raised by the US Department of Justice in a copyright lawsuit against OpenAI "do not apply here."
swframe2 | 6 hours ago
Run the code you want to protect in a cloud function. Cache the user data on the server; modify it on the server, send the diffs to the browser.
</Naive>
<MoreNaive>
Any product that agent can generate from a prompt or reverse engineer will be cloned.
</MoreNaive>
<MostNaive>
Solve problems that make your life better even if cloned.
</MostNaive>
maximegarcia | 6 hours ago
modzu | 2 hours ago
turtlebits | an hour ago
IME, the best route is to disincentivize it, make it harder to copy (obfuscation , etc) or just change your product/lower friction.
If people don't want ads, offer a low-cost ad free option. Having auto-play video ads is extremely distracting.