Tell HN: GitHub refuses to remove cracked copies of my software after a month
Many people are asking AI models to take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download.
There exist tens of such repositories on Github. I want my website to be the only source of a stable version of my program Photopea. I even received emails from people complaining about something in Photopea, and it took several emails to figure out that they are not using Photopea.com (so it ruins my reputation a little).
I reported it to Github on the 4th of September 2026: https://www.photopea.com/g/XKoqqIGv
Today, a month later, I received this response:
Thank you for submitting a DMCA takedown notice. We've reviewed the information you've provided, and based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201.
What do you think I could do? Do you think I should look for a lawyer to deal with it outside the digital world? I really doubt that a real person ever looked at my report, and they probably send this response automatically to 99% of people.
344 comments
Second, I am sorry this is happening to you.
Third, based on GitHub's reply, specifically
> we're unable to confirm a violation of 17 U.S. Code § 1201
they took your submission as 17 U.S. Code § 1201 takedown notice. Maybe you specifically stated this. Maybe it was implied. This is likely not what you want and GitHub's response is likely correct. The reason for this is that § 1201 prohibits circumventing a technological measure. The JS you host on your public site, even if obfuscated, very likely does not qualify for this protection. Another detail - the reason it took long (a month later according to your post) is that after the youtube-dl fiasco, they committed to manual review, legal and technical, of every 1201 takedown notice [0].
Fourth, if you believe these copies are sufficiently reproducing your copyrighted work, what you likely want to do is file a standard copyright infringement 17 U.S Code § 512(c) takedown notice. This still goes through the same DMCA report flow but it should result in a less stringent review process and a faster response.
Fifth and finally, consider asking your favorite LLM to get more context around these laws. Good luck!
[0] https://github.blog/news-insights/policy-news-and-insights/s...
1201(a)(3): "As used in this subsection-- to 'circumvent a technological measure' means to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure, without the authority of the copyright owner"
1. Pay a lawyer or firm that specializes in this sort of thing to play whack a mole for you
2. Accept it as normal losses and ignore it.
Contrary to others claims here, it is not a 500/hour thing to do #1 when dealing with firms that specialize in this. it probably would be if you just hire a random one-off IP lawyer to try and deal with this particular instance.
Trying to deal with it yourself will be increasingly frustrating and time wasting for you. You will also never be able to prevent someone sufficiently motivated from doing stuff like this to your software.
Unless you want to spend your time dealing with those folks instead of building the software, you should hand this part off - it's not a good use of your time, value wise.
Put another way: most companies farm out processing of this sort of request to high volume low cost processing teams. Or AI. Or both. For you this is an important one off. For the person processing it it's one of a hundred tickets they are handling today. You are not going to get very personalized attention and consistency.
I don't claim this is how it should be, etc. I simply claim this is how it realistically is. It would practically require legislative change to have a different thing happen here and while interesting to discuss, that seems outside the scope of your questions, which seemed more practically oriented
As a general rule, you can write off what it costs for you to make something, but not what you lose from not being able to sell it.
Which means for physical goods, you write off the cost to make them, and for digital goods, you can similarly usually deduct development cost to make the software.
In neither case can you write off the amount you would have made had it not been stolen/sale had not been lost.
The practical effect is that because physical goods have a per-unit to-make cost, and most digital goods don't, physical goods get written off per-unit-lost and digital goods do not.
At least, this is the most general answer I can give you for that level of general question.
To write something off you have to actually lose the money - writing off is a process to decrease your taxable income by your expenses, unless you're inventing fake expenses (read: performing tax fraud) it doesn't generate a greater amount of money than the expenses.
The bad guys are winning, because the good guys have no legal recourse. The only practical solution is vigilante justice, but that makes you a bad guy.
In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice?
Civil law systems largely aren't about "good" or "bad". Justice there isn't "good guys win" and "bad guys fail". It never has been.
It's about trying to reasonably resolve disputes. That's all. Civil legal systems were created not to enforce morality or social order, but instead to formally resolve disputes. The system is pretty good at doing that. It will never resolve all disputes, let alone resolve all disputes in an "optimal" way (for any possible definition of optimal you come up with). It only tries to do a reasonable job of it.
If your expectation is that the law will stop "bad" actors from acting "badly", i think your expectations are out of whack. Yes it gets tried, but it is a fairly miniscule portion of the system overall, and generally not a very successful part of it. It's also remarkably recent in the history of legal systems. It is a quasi-political thing that the legal system simply isn't good at dealing with, and really is not a good match for it. I think results bear that out so far
You can take that for whatever you want - I can only tell you why the system is there, historically and currently. That doesn't mean you have to like that idea, and you are welcome to rail against it.
Laws are pretty narrow. Laws about theft aren't going to apply to philosophical positions about hypothetical lost ad views from cloning products.
https://i.ytimg.com/vi/EYTEqHBCV5k/maxresdefault.jpg
For a serious take on copyright versus theft, I would defer to the Supreme Court. I post this because it's both authoritative and well-written.
> Since the statutorily defined property rights of a copyright holder have a character distinct from the possessory interest of the owner of simple “goods, wares, [or] merchandise,” interference with copyright does not easily equate with theft, conversion, or fraud. The infringer of a copyright does not assume physical control over the copyright, nor wholly deprive its owner of its use. Infringement implicates a more complex set of property interests than does run-of-the-mill theft, conversion, or fraud.
Or they all just civil matters?
The Justice is the liberation of code from those that wish to seek rent from it.
Guess why trust in democracy itself is eroding everywhere and why even executing a health insurance CEO on broad daylight is not just widely approved but widely beloved.
The rich can get away with anything (Trump's claim of "I could shoot someone on 5th ave and get away" is pretty realistic, to say nothing about the Epstein crap), but if you are poor or, even worse, an immigrant - pray to God to help you because not just will no one else help you, but in the worst case you might end up getting fucked over for seeking help.
An Axios poll showed 17% found the murder "acceptable" or "somewhat acceptable." Curious where you are seeing such wildly different numbers?
https://www.axios.com/2024/12/17/united-healthcare-ceo-killi...
That poll is across the whole population. Among the younger generations, particularly the "terminally online"? A whole different story.
Why don’t you just install GIMP instead of using Photopea?
Source: Official HN FAQ page.
Are patents the only real IP protection left for software?
And would a patent (assuming this application had something patent-worthy to claim) help at all here? As in, in addition to sending a C&D maybe also including language about patent infringement would be more effective?
I know that patents are unpopular for many here (including you, IIRC!) but I think this question is extremely important, especially to anyone who wants to make a living purely off the software alone.
Remember: if no other moats or business models or funding models lend themselves naturally to the software in question, anything bolted on is pretty much already on the slippery slope to enshittification. A mechanism that encouraged people to compensate fairly for the value provided by software would be better for the Internet than what we've got going on today.
But as sibling comment indicates, even that is no longer a guarantee. There are demonstrations and anecdotal accounts of reverse engineering entire features or even small applications, including the backend code, by pointing an LLM at the web UI: https://www.thoughtworks.com/insights/blog/generative-ai/bla...
This is why I'm thinking that patents and other legal means are likely the only way forward to protect software that does not have a natural moat, like network effects or some huge data advantage. That is actually a huge amount of software.
My concern is that without proper protection software without such moats, this will create incentives for people building them to adopt less-than-ideal means of monetizing their work, e.g. the things that lead to enshittification.
Is there an organization working on this?
As an aside, I thought that "cracked" software meant software that has had the copy protection or other access control bypassed or removed, not the alteration of the software functionality itself. If your software was actually cracked then you may have some fairly heavy law in your favor. For better or worse, bypassing access controls (even weak or simple access controls) gets special legal attention.
Less than 7 figures (~1 million) per year -- not per month -- based on previous comment from 2021: https://news.ycombinator.com/item?id=26769141
A later 2023 interview updated it to ~$200k/month (~2.4 million/year) : https://web.archive.org/web/20240606073354/https://saastrapp...
(I'd just quit my job if I had an income like this.)
Remember that there is still quite a bit of friction to doing that, and that many people have better things to do than jump through those hoops.
In addition to the "hire a lawyer" comments in this thread, I suggest building in some heuristics that detect when Photopea is running outside of your domain. They don't need to be "foolproof," but add additional friction to pirating Photopea so that less people will jump through the hoops.
Some historical examples:
- Commercial software in the 1980s and 1990s would burn a hole on the disk, and the software would look for the error when reading that sector.
- Donkey Kong Country would detect that it was pirated by reading the amount of RAM available. (Because SNES backup systems had slightly different runtime properties than the real cartridge.)
More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.
---
Finally, you could consider a business model that relies on server-side functionality for revenue or stickiness, that's hard to replicate merely by pirating the software. (IE, some kind of server-side storage and sharing system.)
If they're using the github.io repo, the web app can be just as accessible as any other site
This is a very frequently repeated point, which is invalid.
Crashing pirated versions do not affect the reputation of the original. It’s an urban legend.
People using pirated versions are perfectly aware of the fact that they are using butchered versions of the original. So when it crashes, chances are it's because of a botched DRM bypass. It's an obvious connection, has always been.
Today, there is little point in trying to slow down software pirates. At best, adding an arbitrary piracy detection only adds anywhere between mere minutes and a few days to the effort to crack software. This is true absent AI assistance or even a meaningful understanding of ASM outside of logical JMP instructions. The author will likely waste more of their time implementing anti-piracy techniques than a software pirate would figuring out which function call results in the program exiting abruptly. I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities. This is in spite of various licensing and contextual checks throughout.
It would slow down a pirate more to have a program modify or decompress itself in memory, but that class of techniques is still more trouble than it's worth. Experienced pirates already know how to deal with those traps. The timeout thing you mentioned is clever, but the type of person who knows enough to disassemble software would think to themselves "wtf does it crash after 5 minutes?", immediately investigate, and identify the source of the crash.
Having a license check is the only thing authors of software should bother with. It provides most people a framework to consider whether they should pay for a product. Most people won't download potential malware from a sketchy website if you offer your product at a fair price. Those who either know how to crack apps or refuse to pay will keep doing what they're doing.
tl;dr Don't fool yourselves into thinking you'll outsmart a kid with Ghidra installed by throwing a glorified if-statement in their path.
EDIT: I'm speaking in the general sense. The same principles apply to an app that runs almost all of its logic in the browser.
There are some, with code consistency cross-checks and such. Cracking them with static code patching can get very time-consuming. Patching them dynamically works, but some have checks for that too. It's not common though for sure.
(again, for the mere intellectual challenge, not to take profit away from someone's work)
Both fortunately and unfortunately, this situation may change as AI models and workflows tailored around reverse engineering improve.
The thing is that Photopea has been extremely obnoxious with giant colorful ads. They take a big portion of the right-side of the screen (anywhere between 1/4th and 1/6th depending on your screen resolution), stealing important real-estate for actual work.
The owner of Photopea also fights ad blockers harshly and he went as far as surreptitiously breaking some features on purpose when it detected that an adblocker was installed (of course with a fair share of false positives), and then showed later a popup telling the user that they lost their work because of the adblocker. I think he eventually backpedaled on this due to the massive backlash.
You can pay to remove the ads but it costs 60€/year. I think few people are willing to pay for that when they just use it 2-3 times a month.
Overall the developer made the friction so extreme that people will do anything to get rid of the DRM entirely and use self-hosted instances. I think Photopea’s days are counted, a community effort to rebuild a similar tool from the ground up will definitely become a thing. The only thing left to say will be farewell Photopea, you served us well.
Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.
I think I will try solving it with a lawyer. But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.
I think anybody in any line of work or life would like that. It's however unlikely to never run into an issue where a lawyer is really needed, so don't hesitate when you realize you need one.
https://youtu.be/jVkLVRt6c1U
The US allows damages per infringement without need to prove an actual loss, and per infringement.
In my experience GH usually does 512(c) takedowns in days; so it taking a month is quite abnormal. OP’s posted response suggests he didn’t file a copyright takedown but rather an anti-circumvention claim; which is a bit special in DMCA law, and generally best avoided when you have merits to do a regular 512(c).
We also don’t have details of the repo. The author has commented on another project that claims to be a LLM _re-implementation_ of Photopea, without directly using source. If that’s the case, it’s entirely understandable why GitHub won’t take it down.
I spent $18k in legal fees over a $22k claim in a construction dispute. I won the suit and was awarded legal fees. So I'm owed $40k plus interest. I've collected exactly $0. The last lawyer I spoke to said I need to cut my losses in legal fees at some point because from a practical standpoint, winning damages isn't the same as collecting them. Especially if the defendant isn't local and has few assets.
It worked for me! And very quickly.
https://news.ycombinator.com/item?id=49832406
But it is a bit crap that this is the only way you can get Github to behave responsibly.
Good luck.
As for DMCA filings, we publish all of them here: https://github.com/github/dmca
I see two from Photopea, one from 2022 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) and one from 2024 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) - could you point to the recent filing?
I work at GH, but am not involved in DMCA filings, and can in no way answer or judge this case, but potentially follow up internally.
Github did take down this https://github.com/spooknik/Photopea-Appimage and other repos in the past, but now, I feel like I talk to a robot. I am happy to hear that they have real employee! :D
Personal(!) opinion: do get a standard template drafted for these cases by a legal professional. You don’t have to retain anyone or sue anyone, but having a consistent, and compliant filing always expedites decisions - this isn’t GitHub specific. Some platforms like YouTube try to abstract this process and end up with the opposite problem of lots of specious claims. Hence the transparency of publishing all notices we receive. Again no idea whether the filing is the issue in this specific case, nor saying you did anything wrong here, just general advice for fewer headaches.
OP, I’m sorry this is happening to you. It must be incredibly frustrating to have people ripping off something you’ve worked on for many years and pass it off as their own work. I would be furious in your position.
I wish I could do something directly to help you but the best I can offer is to echo the best advice others have already given you: it’s time to get a lawyer. That is the one guaranteed route to get GitHub to sit up and take the action they should already have taken on your behalf.
> Do you think I should look for a lawyer to deal with it outside the digital world?
Absolutely. This is a copyright infringement case and there is now an appellate precedent to cite. Gather as much evidence as you can and speak with an IP attorney.
[1] https://www.reuters.com/legal/litigation/unsealed-opinion-sh...
... so virtually no one considers that ruling to be the final word on the topic (sadly).
I don't think it's enforceable or even applicable here. "The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content "
this comment is misleading.
Also TFA is about a much narrower ruling than it first seems:
>The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content — and the appeals court said in a footnote that concerns raised by the US Department of Justice in a copyright lawsuit against OpenAI "do not apply here."
I think we're also going to see the strategy to be to remove the processing and magic sauce from the client and move it to the server where it can't be decompiled and rebuilt with AI.
Also if it could recreate it that would be fine, because it would be doing so without having access to the source.
This doesn't sound that hard to automate these days.
I find it unlikely that photopea was never scraped for AI training considering they are looking so hard for new material they started buying up and scanning old books.
SaaS killed Open Source with it, two decades ago.
I'd wager we will start to see more web apps like this have greater obfuscation and dependencies on operating on a particular domain. Sure AI can help to circumvent many things, but at a certain point they pay-off may not be worth the effort.
The magic sauce haven't been in the client for many applications for years. Google barely has any application that runs on desktop OS even though they could have released them.
It's a 1-man operation so it may have not have been financially viable to architect the app as server-based.
- server-based : must invest a lot more money in server farms and extra disk storage, or pay high AWS cloud fees. E.g. if a million users do a blur or denoise filter, all that cpu processing has to happen on the servers, and massive disk space to hold the intermediate files, and extra bandwidth costs to send the changed bytes back to the client.
- client-based : just ship Javascript blobs to end users' web browsers because the blur/denoise/etc filters happen on the desktop.
Also, this type of pixel-editing software still needs a ton of client-side Javascript to behave like a Photoshop clone because users want to see interactive changes as they dynamically slide the blur/noise/etc settings. Round-tripping that with extra server latency is not a fluid UI experience.
We can't confidently replay the past and say that starting it as server-side app from the very beginning means he'd have the same $million in revenue today. Instead, the extra server costs and UI jankiness could have doomed the project.
It's a business decision, and I'm not sure if they made the right decision. Most client-only web applications are open source because they know there is no business in selling it as a service. Photopea somehow is an exception, but its business model is getting questionable which is not a surprise at all.
It's also possible to use a combination of cloud based and local computation. Figma is doing quite well in that regard, especially with the use of WebAssembly. No doubt that potentially means more work, and potentially forcing users to create account etc. But hey, that's a business decision as well. If you don't do anything but just keep everything in JavaScript, this was going to happen.
Server-based photoshop clone sounds more like VNC/RDP, for this sort of thing client processing is a better UX.
Right now, the settled law is that such an LLM reproduction is 100% legal.
If you really want to protect your software in the years to come, you might have to seriously consider starting some sort of popular political movement to address this issue in copyright law.
Current models can already do a full reproduction of anything with source code available (e.g. JavaScript...), and there's already been some poor-quality Photoshop knockoffs.
Or perhaps the people should admit that copyright, an artificial construct which is not rooted in natural property, was inherently broken and is not (or at least no longer is) a net benefit to the society and simply adapt around it.
I’m personally waiting for LLMs to get so good that I can make music and movies based on my favorite ones. I probably could never release it to the public, but being able to make it and enjoy it myself would be amazing.
I have agents maintaining several patches to my main tools, not forking, not sharing (some have no interest), personal adjustments
There is basically zero pushback to generated code. All the crazy Minecraft in GTA type mods that came out in the last couple weeks are obviously vibe coded but no one cares because they play good and surprisingly bug free.
If he put in AI visuals as in generated textures then it's different, because that's way more visible and gets labeled as slop immediately. There's also the (accurate imo) perception that AI is taking artists jobs against their will but coders adopted it on their own and benefit from it, so using it for code is ethical from a labor rights POV.
Modifying/modding/remixing software was simply not as feasible as music, but LLMs made it possible.
Copyright, patents and IP are the evolution of our (Western) way of converting research into a form of financial investment.
And a big church could employ lots of them, and thereby stimulate the economy. It seems that the Baroque Era and churches crammed to the rafters with art, may be an artifact of a very good job market for those architects, craftsmen and artists!
Yeah... you could copy some sheet music and share it around, but it still required skilled musicians to perform, play and sing it. And nobody was taking photos or uploading JPEGs of your art and sculpture, so it was fairly locked-in that people needed to visit, and see it in context. So it stood to reason that you could probably reconstruct Noah's Ark from the fragments of True Cross that were circulating around Europe... and how many fingers did your favorite saint really have?
Copyright-free church economics have sort of fallen apart since then. However, museums, arena concerts, theaters and the rest, they have all taken pages from the Church playbooks. The fact that a church can still draw in hundreds for a show with great production values, every week or daily, seems dull and unremarkable now, but a good rock concert or museum collection can evoke the same "goin' to church" fervor in people who like that kind of stuff.
Won't work this year, but it probably will next year. Copyright is done.
That said, I mostly end up using open source for the same reason
Feed a bunch of SaaS screenshots to LLM and you get a GTK+ app for yourself.
How so? Interfaces are not copyrightable, but that it not the same as dissecting a js bundle and copying the implementations. Are we sure these LLM are keeping sanitary habits there?
several courts have ruled Ai output is not copyrightable, I am unaware of any co-authored cases
But, the use of LLMs is not disqualifying. To qualify for copyright protection your work simply must have a sufficient degree of human authorship.
However this is just about protection, not infringement.
If you use an LLM to generate something and that LLM just happens to output something that another human wrote, you may be liable for copyright infringement.
https://www.jonesday.com/en/insights/2025/02/copyrightabilit...
I'm not convinced we are actually at the point where something like Photoshop is trivial to rebuild. That involves a lot of manual QA and the expertise in actually knowing how everything should work.
That said, give it 6-12 months and I won't be surprised if they can one-shot "create a future-complete clone of Photoshop, make no mistakes"
Where did you hear that? Because it is 100% untrue and is the opposite of current legal guidance from reputable legal expert
The current fun loophole is to have the LLM decompile the existing code, build unit tests around that, and then have a different LLM model build the code that satisfies those tests.
Either way, you can absolutely get a "clean room" result from an LLM.
And there’s a huge foot gun here in that many LLMs have been trained on copyrighted code that may include the subject of your reimplementation in some cases, which pose a risk of breaking the clean room.
My understanding was that re-invention without copying any code is legal. But scraping code from the browser and re-using it is not. I'd love to know how that plays in the courts with LLMs, as their entire model comes from copying code as training material, not writing new code from scratch.
Regular humans train on copying code too (Stack Overflow, etc.) so unless they were trained on that specific codebase, I really doubt you have any sort of legal standing. And given how little compensation the authors got when their work got trained on, I wouldn't hold out hope for a big payout even then...