Tell HN: GitHub refuses to remove cracked copies of my software after a month

567 points by IvanK_net · 344 comments
I am a developer of https://www.photopea.com, a popular photo editor that runs in a web browser.

Many people are asking AI models to take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download.

There exist tens of such repositories on Github. I want my website to be the only source of a stable version of my program Photopea. I even received emails from people complaining about something in Photopea, and it took several emails to figure out that they are not using Photopea.com (so it ruins my reputation a little).

I reported it to Github on the 4th of September 2026: https://www.photopea.com/g/XKoqqIGv

Today, a month later, I received this response:

Thank you for submitting a DMCA takedown notice. We've reviewed the information you've provided, and based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201.

What do you think I could do? Do you think I should look for a lawyer to deal with it outside the digital world? I really doubt that a real person ever looked at my report, and they probably send this response automatically to 99% of people.

344 comments

First off, let me get this out of the way - I am not a lawyer. If you want a legal advice talk to a lawyer.

Second, I am sorry this is happening to you.

Third, based on GitHub's reply, specifically

> we're unable to confirm a violation of 17 U.S. Code § 1201

they took your submission as 17 U.S. Code § 1201 takedown notice. Maybe you specifically stated this. Maybe it was implied. This is likely not what you want and GitHub's response is likely correct. The reason for this is that § 1201 prohibits circumventing a technological measure. The JS you host on your public site, even if obfuscated, very likely does not qualify for this protection. Another detail - the reason it took long (a month later according to your post) is that after the youtube-dl fiasco, they committed to manual review, legal and technical, of every 1201 takedown notice [0].

Fourth, if you believe these copies are sufficiently reproducing your copyrighted work, what you likely want to do is file a standard copyright infringement 17 U.S Code § 512(c) takedown notice. This still goes through the same DMCA report flow but it should result in a less stringent review process and a faster response.

Fifth and finally, consider asking your favorite LLM to get more context around these laws. Good luck!

[0] https://github.blog/news-insights/policy-news-and-insights/s...

Circumventing a technological measure has been interpreted extremely broadly. Deobfuscation could be covered.
eli
This is bad advice. Obfuscated JS qualifies.

1201(a)(3): "As used in this subsection-- to 'circumvent a technological measure' means to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure, without the authority of the copyright owner"

Obfuscated JS can be re-hosted as is, and you can probably remove the ads with newly added JS code.
eli
Or just visit the real site and use an ad blocker? Re-hosting it would obviously be copyright infringement.
Maxatar
Ad-blocking breaks the original site. A lot of functionality stops working properly.
eli
Sure, seems only fair that if you can try to block ads, the app can try to detect ad blockers.
keeda
The problem is that AI can probably rewrite this JS de novo simply by observing its behavior and without de-obfuscating it.
Or just ask first AI to create specs and another AI to do clean room implementation?
eli
I think you would just end up with yet another slopcoded photoshop clone
This would be legal, by the way.
are they tools to deobfuscate (covered) or just deobfuscated copies (not covered)?
Indeed, a 512(c) takedown notice is the way to do it. GitHub is extremely unlikely to ignore it. I run user generated content websites and would never ignore a notice. You definitely don't need to hire a lawyer to write it either. Just follow the notification guidelines in 17 U.S Code § 512(c)(3).
IP lawyer here - I can't give you actual legal advice because you aren't my client, but generally, you have two options here, neither of which will be surprising, or very satisfying:

1. Pay a lawyer or firm that specializes in this sort of thing to play whack a mole for you

2. Accept it as normal losses and ignore it.

Contrary to others claims here, it is not a 500/hour thing to do #1 when dealing with firms that specialize in this. it probably would be if you just hire a random one-off IP lawyer to try and deal with this particular instance.

Trying to deal with it yourself will be increasingly frustrating and time wasting for you. You will also never be able to prevent someone sufficiently motivated from doing stuff like this to your software.

Unless you want to spend your time dealing with those folks instead of building the software, you should hand this part off - it's not a good use of your time, value wise.

Put another way: most companies farm out processing of this sort of request to high volume low cost processing teams. Or AI. Or both. For you this is an important one off. For the person processing it it's one of a hundred tickets they are handling today. You are not going to get very personalized attention and consistency.

I don't claim this is how it should be, etc. I simply claim this is how it realistically is. It would practically require legislative change to have a different thing happen here and while interesting to discuss, that seems outside the scope of your questions, which seemed more practically oriented

I've spent 0 seconds googling this so excuse the dumbfuck question but: is there any precedent or convention for writing off the stolen goods as losses? I'm pretty sure physical goods from businesses qualify but what about this??
ktm5j
Digital losses to piracy sounds like something that would be impossible to quantify.. even if they can prove that people are downloading these pirated copies, that's not proof that the downloader was ever going to pay for the software in the first place.
DannyBee OC
Physical/digital has the same answer, just different effect.

As a general rule, you can write off what it costs for you to make something, but not what you lose from not being able to sell it.

Which means for physical goods, you write off the cost to make them, and for digital goods, you can similarly usually deduct development cost to make the software.

In neither case can you write off the amount you would have made had it not been stolen/sale had not been lost.

The practical effect is that because physical goods have a per-unit to-make cost, and most digital goods don't, physical goods get written off per-unit-lost and digital goods do not.

At least, this is the most general answer I can give you for that level of general question.

Could you just make a CICD process that for each minting of a software license it cost a person's time to review and accept and then the wages for that individual become the write off. I.E. Convolute the software delivery process so that like a physical good, it has a per-unit to license cost to recoup. Or would that be argued as it could have just been automated and it's not really a real loss leader just bad policy?
You don't lose this time for pirated copies of your software, as I assume you aren't taking this person's time to create a license for pirates.

To write something off you have to actually lose the money - writing off is a process to decrease your taxable income by your expenses, unless you're inventing fake expenses (read: performing tax fraud) it doesn't generate a greater amount of money than the expenses.

Why would you incur additional expenses just to be able to write them off?
What I am hearing is “there will be no justice here for you.”

The bad guys are winning, because the good guys have no legal recourse. The only practical solution is vigilante justice, but that makes you a bad guy.

In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice?

The question is not how then is one supposed to trust the law, because you already know the answer. The question is what one does about it.
This is HN so nothing else to expect than Big Tech people giving us the scoop with the tagline "let's be realistic here".
I imagine most people don't expect actual justice in life.
DannyBee OC
Let's separate criminal and civil here, because this is all civil law.

Civil law systems largely aren't about "good" or "bad". Justice there isn't "good guys win" and "bad guys fail". It never has been.

It's about trying to reasonably resolve disputes. That's all. Civil legal systems were created not to enforce morality or social order, but instead to formally resolve disputes. The system is pretty good at doing that. It will never resolve all disputes, let alone resolve all disputes in an "optimal" way (for any possible definition of optimal you come up with). It only tries to do a reasonable job of it.

If your expectation is that the law will stop "bad" actors from acting "badly", i think your expectations are out of whack. Yes it gets tried, but it is a fairly miniscule portion of the system overall, and generally not a very successful part of it. It's also remarkably recent in the history of legal systems. It is a quasi-political thing that the legal system simply isn't good at dealing with, and really is not a good match for it. I think results bear that out so far

You can take that for whatever you want - I can only tell you why the system is there, historically and currently. That doesn't mean you have to like that idea, and you are welcome to rail against it.

Since when is "theft" civil? Perhaps we don't consider this "theft", and as such, we feel this isn't criminal.
qup
It's not theft, since something wasn't taken.

Laws are pretty narrow. Laws about theft aren't going to apply to philosophical positions about hypothetical lost ad views from cloning products.

xtajv
Because a picture is worth a thousand words... this is a friendly reminder that the FBI does not agree.

https://i.ytimg.com/vi/EYTEqHBCV5k/maxresdefault.jpg

That's always been a misleading banner. Notice that it never uses the phrase theft, and that it only talks about criminal copyright infringement, but doesn't actually tie that back to the copying of a single movie. It's basically FUD.

For a serious take on copyright versus theft, I would defer to the Supreme Court. I post this because it's both authoritative and well-written.

> Since the statutorily defined property rights of a copyright holder have a character distinct from the possessory interest of the owner of simple “goods, wares, [or] merchandise,” interference with copyright does not easily equate with theft, conversion, or fraud. The infringer of a copyright does not assume physical control over the copyright, nor wholly deprive its owner of its use. Infringement implicates a more complex set of property interests than does run-of-the-mill theft, conversion, or fraud.

Nothing tangible, something you created was taken though. There certainly are copyright laws, enforcement is the problem due to the laissez-faire attitude of many.
qup
No, it wasn't taken. It was copied.
Aren’t all the people getting in trouble for downloading music and movies from file sharing sites it bittorrent getting charged (or threat there of) with theft?

Or they all just civil matters?

It's all civil.
What if writing proprietary and/or non-free software was the real evil? LLMs have made everything open source. All software is free now.

The Justice is the liberation of code from those that wish to seek rent from it.

vuurmot
Communism, but I pay rent to Sam Altman
will be free when everyone owns the means to make it, instead you're going to rent the compute to make the software to escape the rent
> In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice?

Guess why trust in democracy itself is eroding everywhere and why even executing a health insurance CEO on broad daylight is not just widely approved but widely beloved.

The rich can get away with anything (Trump's claim of "I could shoot someone on 5th ave and get away" is pretty realistic, to say nothing about the Epstein crap), but if you are poor or, even worse, an immigrant - pray to God to help you because not just will no one else help you, but in the worst case you might end up getting fucked over for seeking help.

> executing a health insurance CEO on broad daylight is not just widely approved but widely beloved.

An Axios poll showed 17% found the murder "acceptable" or "somewhat acceptable." Curious where you are seeing such wildly different numbers?

https://www.axios.com/2024/12/17/united-healthcare-ceo-killi...

I mean, 17% as a whole. But when you have the younger generations going as high as 40% saying that murder was acceptable (and note the question phrasing here is about as negatively charged as it can get) you surely have to see the disconnect here.
> An Axios poll showed 17% found the murder "acceptable" or "somewhat acceptable."

That poll is across the whole population. Among the younger generations, particularly the "terminally online"? A whole different story.

Younger, terminally online people are largely degenerates. You’re just being sensationalist.
bsoqk
This is what HN has devolved into: someone taking adware and removing the ads is a "bad guy".
That is bad...
cpach
Well, shouldn’t that be up to the original developer? He made a product and let people use it for free. But no-one is forced to use it. And there are other image editors without any ads. Some are proprietary, and some are FOSS, e.g. GIMP.
I don't know. Shouldn't it be up to Microsoft whether my copy of Windows reports back all of my personal data? Shouldn't it be up to Dell whether my computer can only boot Microsoft operating systems?
cpach
What does that have to do with software that is financed by ads?

Why don’t you just install GIMP instead of using Photopea?

Exactly. Did you know that leaving the room during a TV commercial break is theft of service - or so argued TV channel companies in court once?
cpach
Uhm, okey. But how is that related to Photopea? Are you arguing that copyright laws are void for software that display ads?
How are you defining "justice"/"bad guys"? Under HN rules, if a company requires payment, it's explicitly only OK to post if a “workaround” to avoid paying is available. Additionally, HN explicitly says it's OK for HN comments to ask how to get around payment requirements, and for HN users to help other users to get around payment requirements.

Source: Official HN FAQ page.

What I am hearing is "if you can't beat em, join em". If there is no justice for software pirates then we should all pirate everything, at least from companies we dislike.
tim333
Not a lawyer but I have friends get some results getting an LLM to send threatening lawyer type letters.
keeda
Since you're here and on topic, a question that has been at the back of my mind because I feel that soon most software creators will be in this boat, with AI rapidly becoming able to clone software from observing behavior alone:

Are patents the only real IP protection left for software?

And would a patent (assuming this application had something patent-worthy to claim) help at all here? As in, in addition to sending a C&D maybe also including language about patent infringement would be more effective?

I know that patents are unpopular for many here (including you, IIRC!) but I think this question is extremely important, especially to anyone who wants to make a living purely off the software alone.

Remember: if no other moats or business models or funding models lend themselves naturally to the software in question, anything bolted on is pretty much already on the slippery slope to enshittification. A mechanism that encouraged people to compensate fairly for the value provided by software would be better for the Internet than what we've got going on today.

nradov
The only effective protection for software IP is hiding the logic on servers you control (SaaS). Anything released to execute on client hardware can be decompiled and cloned. This has always been the case but LLMs have made the issue more obvious.
modzu
there is no more software IP. ai does not need source: it can infer or deduce the logic or algos. and in the case of private software dont think it hasn't been sucked up too
keeda
Agreed, only I would rephrase it as, "hiding logic on servers is the best technical / non-IP protection for software" -- consider that IP largely exists to protect things that other means cannot!

But as sibling comment indicates, even that is no longer a guarantee. There are demonstrations and anecdotal accounts of reverse engineering entire features or even small applications, including the backend code, by pointing an LLM at the web UI: https://www.thoughtworks.com/insights/blog/generative-ai/bla...

This is why I'm thinking that patents and other legal means are likely the only way forward to protect software that does not have a natural moat, like network effects or some huge data advantage. That is actually a huge amount of software.

My concern is that without proper protection software without such moats, this will create incentives for people building them to adopt less-than-ideal means of monetizing their work, e.g. the things that lead to enshittification.

nradov
Patents can be somewhat effective for vertical market software sold by companies operating in countries with effective rule of law. But for horizontal or consumer software the pirates and cloners can operate servers in other shithole countries beyond the reach of law enforcement. We'll probably see more political pressure to respond to that with widespread IP address blocks at national borders. Eventually every country may have some variant of "The Great Firewall of China". (I don't think that's a good thing, just stating that it's likely to become more prevalent.)
xtajv
> It would practically require legislative change to have a different thing happen here and while interesting to discuss, that seems outside the scope of your questions, which seemed more practically oriented

Is there an organization working on this?

JohnFen
You should discuss this with an attorney that is experienced with IP law to see what your options really are. IP law is very complex and sometimes very surprising. You need expert legal advice, not advice from the HN crowd.

As an aside, I thought that "cracked" software meant software that has had the copy protection or other access control bypassed or removed, not the alteration of the software functionality itself. If your software was actually cracked then you may have some fairly heavy law in your favor. For better or worse, bypassing access controls (even weak or simple access controls) gets special legal attention.

What is the cost for doing this, out of curiosity? If OP only earns a trickle of revenue from their site, it probably isn’t even worth the money (?)
Onavo
He earns 7 figs a month from it iirc, was featured many times on HN as a successful indie hacker.
If that’s true, he doesn’t need free legal advice from us.
msdz
True, but then again, the post is titled “Tell HN”, not “Ask HN”. Maybe it’s just a case of the poster trying to raise awareness.
pluc
... they're just trying to get the attention of someone at GH that can do anything OR create bad press that they then have to deal with. But pressuring them on HN to act about their sub-par anything is.. arduous, given their.. tolerance.
jasode
>He earns 7 figs a month from it iirc,

Less than 7 figures (~1 million) per year -- not per month -- based on previous comment from 2021: https://news.ycombinator.com/item?id=26769141

A later 2023 interview updated it to ~$200k/month (~2.4 million/year) : https://web.archive.org/web/20240606073354/https://saastrapp...

fg137
Still enough to hire a lawyer and at least do a few consultation sessions. That's a necessary business expense.

(I'd just quit my job if I had an income like this.)

That comment was over 5 years ago. That's a long time, and from estimates he has millions of users now. Definitely making big money.
A lot of lawyers will give a free consultation, and in my experience (not for IP) they will give decent expert advice for free. No harm calling them.
Shank
Most state bar associations have a free consultation line that will refer you to a reputable lawyer to start with and do basic consultation on where your issue should go and how much it will be. If I had to guess, getting advice is probably $100 and having a lawyer send a letter is $250-500.
Scaled
IP lawyers tend to be at the more expensive end, typical billing rate in US of $500/hr last I looked. But yes, being able to do a letter quickly is probable.
gwbas1c
> take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download

Remember that there is still quite a bit of friction to doing that, and that many people have better things to do than jump through those hoops.

In addition to the "hire a lawyer" comments in this thread, I suggest building in some heuristics that detect when Photopea is running outside of your domain. They don't need to be "foolproof," but add additional friction to pirating Photopea so that less people will jump through the hoops.

Some historical examples:

- Commercial software in the 1980s and 1990s would burn a hole on the disk, and the software would look for the error when reading that sector.

- Donkey Kong Country would detect that it was pirated by reading the amount of RAM available. (Because SNES backup systems had slightly different runtime properties than the real cartridge.)

More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.

---

Finally, you could consider a business model that relies on server-side functionality for revenue or stickiness, that's hard to replicate merely by pirating the software. (IE, some kind of server-side storage and sharing system.)

> Remember that there is still quite a bit of friction to doing that

If they're using the github.io repo, the web app can be just as accessible as any other site

abcd_f
> More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.

This is a very frequently repeated point, which is invalid.

Crashing pirated versions do not affect the reputation of the original. It’s an urban legend.

People using pirated versions are perfectly aware of the fact that they are using butchered versions of the original. So when it crashes, chances are it's because of a botched DRM bypass. It's an obvious connection, has always been.

Techniques like what you describe made a little more sense when the means to even figure them out were less feasible for the average person, especially before the web had much information on reverse engineering, when powerful debugging tools weren't as accessible or free.

Today, there is little point in trying to slow down software pirates. At best, adding an arbitrary piracy detection only adds anywhere between mere minutes and a few days to the effort to crack software. This is true absent AI assistance or even a meaningful understanding of ASM outside of logical JMP instructions. The author will likely waste more of their time implementing anti-piracy techniques than a software pirate would figuring out which function call results in the program exiting abruptly. I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities. This is in spite of various licensing and contextual checks throughout.

It would slow down a pirate more to have a program modify or decompress itself in memory, but that class of techniques is still more trouble than it's worth. Experienced pirates already know how to deal with those traps. The timeout thing you mentioned is clever, but the type of person who knows enough to disassemble software would think to themselves "wtf does it crash after 5 minutes?", immediately investigate, and identify the source of the crash.

Having a license check is the only thing authors of software should bother with. It provides most people a framework to consider whether they should pay for a product. Most people won't download potential malware from a sketchy website if you offer your product at a fair price. Those who either know how to crack apps or refuse to pay will keep doing what they're doing.

tl;dr Don't fool yourselves into thinking you'll outsmart a kid with Ghidra installed by throwing a glorified if-statement in their path.

EDIT: I'm speaking in the general sense. The same principles apply to an app that runs almost all of its logic in the browser.

eps
> I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities

There are some, with code consistency cross-checks and such. Cracking them with static code patching can get very time-consuming. Patching them dynamically works, but some have checks for that too. It's not common though for sure.

Yeah, I'm sure they're out there, but it's very rare in my experience. I'm a micro-brain when it comes to cracking software, and I've almost never encountered this, whether it's small fry software or something from Microsoft or Autodesk. There was some software with debugger detection I came across once (can't remember which it was), but that's the kind of thing where lots of existing workarounds often exist by other crack-ers.
Timon3
I'd recommend taking a look at DRM for games. It's been a while since I read anything, but AFAIK Denuvo is still effective enough to protect newly released games for weeks.
If I was a much younger man, I would gladly spend weeks or months out of my life to try and break a Denuvo protected game. haha

(again, for the mere intellectual challenge, not to take profit away from someone's work)

I've spent some years in gamedev and doing PC versions was a big part of it. I have seen countless attempts at 'code consistency cross-checks' and they all have been defeated. The only thing that came close was Denuvo. You may want to read up on it before dismissing it. It's sad that folks here will downvote and hate anything about it. What it changed is that publishers got their money from people playing on PC and some of it was spent on developers to actually improve future games =)
I wouldn't dismiss Denuvo. It is intended for a particular use case, which is games where a week or more delay between the release of a game and the appearance of a crack would make a meaningful difference. The payoff wouldn't be nearly the same for a lot of other software.

Both fortunately and unfortunately, this situation may change as AI models and workflows tailored around reverse engineering improve.

mattm
Another example I remember from quite a while ago. The site owner realized that the copycat site was displaying images sourced directly from his site. Since he had control over them, he changed the data to return less-than-appropriate images. I believe the copycat site ended up taking their site down after that.
> Remember that there is still quite a bit of friction to doing that, and that many people have better things to do than jump through those hoops

The thing is that Photopea has been extremely obnoxious with giant colorful ads. They take a big portion of the right-side of the screen (anywhere between 1/4th and 1/6th depending on your screen resolution), stealing important real-estate for actual work.

The owner of Photopea also fights ad blockers harshly and he went as far as surreptitiously breaking some features on purpose when it detected that an adblocker was installed (of course with a fair share of false positives), and then showed later a popup telling the user that they lost their work because of the adblocker. I think he eventually backpedaled on this due to the massive backlash.

You can pay to remove the ads but it costs 60€/year. I think few people are willing to pay for that when they just use it 2-3 times a month.

Overall the developer made the friction so extreme that people will do anything to get rid of the DRM entirely and use self-hosted instances. I think Photopea’s days are counted, a community effort to rebuild a similar tool from the ground up will definitely become a thing. The only thing left to say will be farewell Photopea, you served us well.

Talking about the devil, a few days ago this happened: https://github.com/storytold/photocraft
IvanK_net OP
Hey guys, thank you all very much for your comments! I just woke up, I did not really believe my post would get this much attention, so thanks!

Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.

I think I will try solving it with a lawyer. But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.

brnt
> But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.

I think anybody in any line of work or life would like that. It's however unlikely to never run into an issue where a lawyer is really needed, so don't hesitate when you realize you need one.

Someone recently posted a link to Mike Monteiro's "Fuck You Pay Me" talk. It's one for the ages:

https://youtu.be/jVkLVRt6c1U

Qwuke
I've used Photopea for small editing before, and even though it's not my daily driver, it's a really cool project.
graemep
A lawyer will probably get you damages for the infringement and is less hassle than trying the whole process yourself.
gpugreg
I could find are a bunch of Photopea repositories on GitHub, but the authors are all either from China or Russia, so getting damages for infringement will be difficult to enforce. Hiring a lawyer sounds like a waste of money to me.
graemep
You might be able to get damages from github, especially as they have ignored a notification that there was infringing material. A lawyer would know.

The US allows damages per infringement without need to prove an actual loss, and per infringement.

dannyw
We don’t know if OP filed the DMCA “optimally”.

In my experience GH usually does 512(c) takedowns in days; so it taking a month is quite abnormal. OP’s posted response suggests he didn’t file a copyright takedown but rather an anti-circumvention claim; which is a bit special in DMCA law, and generally best avoided when you have merits to do a regular 512(c).

We also don’t have details of the repo. The author has commented on another project that claims to be a LLM _re-implementation_ of Photopea, without directly using source. If that’s the case, it’s entirely understandable why GitHub won’t take it down.

Github supposedly manually verifies 1201 claims, which would explain the long wait on the response.
kevin42
Sadly though, you have to do the cost/benefit analysis of the legal process and your likelihood of recovering anything.

I spent $18k in legal fees over a $22k claim in a construction dispute. I won the suit and was awarded legal fees. So I'm owed $40k plus interest. I've collected exactly $0. The last lawyer I spoke to said I need to cut my losses in legal fees at some point because from a practical standpoint, winning damages isn't the same as collecting them. Especially if the defendant isn't local and has few assets.

>Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.

It worked for me! And very quickly.

https://news.ycombinator.com/item?id=49832406

But it is a bit crap that this is the only way you can get Github to behave responsibly.

Good luck.

Is there a ticket code or other contact you've been in touch with?

As for DMCA filings, we publish all of them here: https://github.com/github/dmca

I see two from Photopea, one from 2022 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) and one from 2024 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) - could you point to the recent filing?

I work at GH, but am not involved in DMCA filings, and can in no way answer or judge this case, but potentially follow up internally.

IvanK_net OP
Thanks! One is Ticket 4822535, another is Ticket 4726557.

Github did take down this https://github.com/spooknik/Photopea-Appimage and other repos in the past, but now, I feel like I talk to a robot. I am happy to hear that they have real employee! :D

IvanK_net OP
Github asked me to file a new ticket, so it is all under Ticket 4833281 now.
summarity OC
Good to know, I had let the team know. It’s handled by the appropriate folks so I won’t see further updates, but this should be in good hands now.

Personal(!) opinion: do get a standard template drafted for these cases by a legal professional. You don’t have to retain anyone or sue anyone, but having a consistent, and compliant filing always expedites decisions - this isn’t GitHub specific. Some platforms like YouTube try to abstract this process and end up with the opposite problem of lots of specious claims. Hence the transparency of publishing all notices we receive. Again no idea whether the filing is the issue in this specific case, nor saying you did anything wrong here, just general advice for fewer headaches.

Man, some of the comments this is getting are absolutely wild.

OP, I’m sorry this is happening to you. It must be incredibly frustrating to have people ripping off something you’ve worked on for many years and pass it off as their own work. I would be furious in your position.

I wish I could do something directly to help you but the best I can offer is to echo the best advice others have already given you: it’s time to get a lawyer. That is the one guaranteed route to get GitHub to sit up and take the action they should already have taken on your behalf.

hgs3
The 3rd U.S. Circuit Court of Appeals recently ruled [1] that using AI to train on a competitor's copyrighted material to build a competing product is _not_ fair use. This is a recent ruling (September 30, 2026). GitHub policy has surely not caught up yet and who knows when it will.

> Do you think I should look for a lawyer to deal with it outside the digital world?

Absolutely. This is a copyright infringement case and there is now an appellate precedent to cite. Gather as much evidence as you can and speak with an IP attorney.

[1] https://www.reuters.com/legal/litigation/unsealed-opinion-sh...

... and we all know our idiotic/corrupt Supreme Court can and likely will overrules that very sensible ruling with something crazy ...

... so virtually no one considers that ruling to be the final word on the topic (sadly).

How is this enforceable with llms if they train on generalist material, which is already the case?

I don't think it's enforceable or even applicable here. "The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content "

this comment is misleading.

keeda
You're right that this is a copyright infringement case, but I'm not sure if AI is relevant here, as it seems like a pretty straightforward rip-off.

Also TFA is about a much narrower ruling than it first seems:

>The 3rd Circuit distinguished Thomson Reuters' case from other AI training cases. Unlike the technology in those cases, Ross' search engine did not feature generative AI — AI that creates new content — and the appeals court said in a footnote that concerns raised by the US Department of Justice in a copyright lawsuit against OpenAI "do not apply here."

I think we're going to see a lot more of this going forward.

I think we're also going to see the strategy to be to remove the processing and magic sauce from the client and move it to the server where it can't be decompiled and rebuilt with AI.

You think AI can't recreate it based on the outputs?
ChrisRR
Maybe it can, but that's not what this post or comment is about
schnebbau OC
1:1? No, because AI won't know all the outputs, only the ones you show it.

Also if it could recreate it that would be fine, because it would be doing so without having access to the source.

pixl97
>only the ones you show it

This doesn't sound that hard to automate these days.

> because it would be doing so without having access to the source

I find it unlikely that photopea was never scraped for AI training considering they are looking so hard for new material they started buying up and scanning old books.

When it can do that, the people can also describe the output, i.e. the fact that your original website even exists is irrelevant for what people are able to do.
This ship has already sailed, and most people in tech circles didn't even notice.

SaaS killed Open Source with it, two decades ago.

Apps like photopea exist because of client side processing. They shift cost to client compute and that makes them supportable by indie devs.

I'd wager we will start to see more web apps like this have greater obfuscation and dependencies on operating on a particular domain. Sure AI can help to circumvent many things, but at a certain point they pay-off may not be worth the effort.

fg137
Since these clones already exist, it means that even if Photopea moves to server based (which it should have been in the first place), the code is around and will work forever.

The magic sauce haven't been in the client for many applications for years. Google barely has any application that runs on desktop OS even though they could have released them.

jasode
>, it means that even if Photopea moves to server based (which it should have been in the first place),

It's a 1-man operation so it may have not have been financially viable to architect the app as server-based.

- server-based : must invest a lot more money in server farms and extra disk storage, or pay high AWS cloud fees. E.g. if a million users do a blur or denoise filter, all that cpu processing has to happen on the servers, and massive disk space to hold the intermediate files, and extra bandwidth costs to send the changed bytes back to the client.

- client-based : just ship Javascript blobs to end users' web browsers because the blur/denoise/etc filters happen on the desktop.

Also, this type of pixel-editing software still needs a ton of client-side Javascript to behave like a Photoshop clone because users want to see interactive changes as they dynamically slide the blur/noise/etc settings. Round-tripping that with extra server latency is not a fluid UI experience.

We can't confidently replay the past and say that starting it as server-side app from the very beginning means he'd have the same $million in revenue today. Instead, the extra server costs and UI jankiness could have doomed the project.

fg137
I understand all of that.

It's a business decision, and I'm not sure if they made the right decision. Most client-only web applications are open source because they know there is no business in selling it as a service. Photopea somehow is an exception, but its business model is getting questionable which is not a surprise at all.

It's also possible to use a combination of cloud based and local computation. Figma is doing quite well in that regard, especially with the use of WebAssembly. No doubt that potentially means more work, and potentially forcing users to create account etc. But hey, that's a business decision as well. If you don't do anything but just keep everything in JavaScript, this was going to happen.

flomo
> server based (which it should have been in the first place)

Server-based photoshop clone sounds more like VNC/RDP, for this sort of thing client processing is a better UX.

Regardless of what you do now, I think you should be prepared for the upcoming reality that LLMs are going to be able to reproduce software, feature-perfect, in a way that does not currently violate copyright law.

Right now, the settled law is that such an LLM reproduction is 100% legal.

If you really want to protect your software in the years to come, you might have to seriously consider starting some sort of popular political movement to address this issue in copyright law.

Current models can already do a full reproduction of anything with source code available (e.g. JavaScript...), and there's already been some poor-quality Photoshop knockoffs.

tgma
> popular political movement to address this issue in copyright law.

Or perhaps the people should admit that copyright, an artificial construct which is not rooted in natural property, was inherently broken and is not (or at least no longer is) a net benefit to the society and simply adapt around it.

I was watching a video talking about how a world before copyright allowed innovation to spread quickly and allowed people miles away to iterate faster. Even if LLMs reproducing feature perfect software is deemed a copyright violation, people will just do it privately and use the software themselves.

I’m personally waiting for LLMs to get so good that I can make music and movies based on my favorite ones. I probably could never release it to the public, but being able to make it and enjoy it myself would be amazing.

There is something similar happening in the game modding communities. One of my favorite streamers had claude write a little mod to change the UI of KSP so it kept with the larger fanciful theme of the game, over being so sci-fi-ish. He didn't like, he changed it, he's probably not going to release it because of sensitivity in the broader gaming ecosystem.

I have agents maintaining several patches to my main tools, not forking, not sharing (some have no interest), personal adjustments

tancop
> he's probably not going to release it because of sensitivity in the broader gaming ecosystem

There is basically zero pushback to generated code. All the crazy Minecraft in GTA type mods that came out in the last couple weeks are obviously vibe coded but no one cares because they play good and surprisingly bug free.

If he put in AI visuals as in generated textures then it's different, because that's way more visible and gets labeled as slop immediately. There's also the (accurate imo) perception that AI is taking artists jobs against their will but coders adopted it on their own and benefit from it, so using it for code is ethical from a labor rights POV.

I believe it is a lot closer to CSS, some images for buttons that needed inverting, closer to dark mode
tgma
Another thing that can help contextualize this phenomenon is mix tapes, which are fair use in the US.

Modifying/modding/remixing software was simply not as feasible as music, but LLMs made it possible.

That world worked because the ones doing the research were either self-sufficient hermits (often self-sufficient by necessity as they were outcast for "being mad"), financed by the Church or financed by a rich person (usually the fiefdom's ruler, sometimes independent wealth).

Copyright, patents and IP are the evolution of our (Western) way of converting research into a form of financial investment.

Patronage and support of the arts (and sciences) was a great value proposition for Churchmen in old times. You could commission works of music or sculpture or stained glass or what have you, and these were of course well-fitted to be installed or performed in the confines of your church and serve the liturgy. So they were collective goods that were enjoyed by many; they attracted locals and they beautified their surroundings, and they encouraged pilgrimages and stimulated income if you could become particularly distinguished and attractive, based on the beauty lent by your artisans and artists.

And a big church could employ lots of them, and thereby stimulate the economy. It seems that the Baroque Era and churches crammed to the rafters with art, may be an artifact of a very good job market for those architects, craftsmen and artists!

Yeah... you could copy some sheet music and share it around, but it still required skilled musicians to perform, play and sing it. And nobody was taking photos or uploading JPEGs of your art and sculpture, so it was fairly locked-in that people needed to visit, and see it in context. So it stood to reason that you could probably reconstruct Noah's Ark from the fragments of True Cross that were circulating around Europe... and how many fingers did your favorite saint really have?

Copyright-free church economics have sort of fallen apart since then. However, museums, arena concerts, theaters and the rest, they have all taken pages from the Church playbooks. The fact that a church can still draw in hundreds for a show with great production values, every week or daily, seems dull and unremarkable now, but a good rock concert or museum collection can evoke the same "goin' to church" fervor in people who like that kind of stuff.

Only if I as a human being get the same rights to e.g. Microsofts code as they get to mine via legal trickery in your world.
You do. Just point the LLM towards windows.exe and tell it to party on.

Won't work this year, but it probably will next year. Copyright is done.

handoflixue OC
My one big issue there is that "adapt around it" tends to look like cryptic black box "Software as a Service" because that gives you a solid moat against competition / reproductions. I would like to be able to pay for software whose function is wholly transparent to me.

That said, I mostly end up using open source for the same reason

tgma
Is that so? That's just one side of the push and pull.

Feed a bunch of SaaS screenshots to LLM and you get a GTK+ app for yourself.

14u2c
> Right now, the settled law is that such an LLM reproduction is 100% legal.

How so? Interfaces are not copyrightable, but that it not the same as dissecting a js bundle and copying the implementations. Are we sure these LLM are keeping sanitary habits there?

if you've used any Ai in your own code authoring, copyrights may be completely out the window

several courts have ruled Ai output is not copyrightable, I am unaware of any co-authored cases

That doesn't top people producing copies though, just trying to copyright the copies.
it also means that you cannot claim copyright against copiers, the context here being the original has had Ai involvement in the development process
If you only used the output of an LLM, then you don’t qualify.

But, the use of LLMs is not disqualifying. To qualify for copyright protection your work simply must have a sufficient degree of human authorship.

However this is just about protection, not infringement.

If you use an LLM to generate something and that LLM just happens to output something that another human wrote, you may be liable for copyright infringement.

fg137
Are you a lawyer?
Here's an article from Jones Day that confirms what I just said:

https://www.jonesday.com/en/insights/2025/02/copyrightabilit...

I feel like I need to nitpick a little: Models don't need source code available to reproduce software. See all the "full decompilation" projects cropping up. There's no putting this genie back in the box, because LLMs can also "refurbish" a project enough that it ceases to look like the original. People don't bother now because they don't have to, but in a world where they'd get hit with copyright notices, they would.
handoflixue OC
I will say that a lot of the "full decompilation" projects popping up are honestly crap - some are good, but a lot of them just build something that makes for a good screenshot or promotional video.

I'm not convinced we are actually at the point where something like Photoshop is trivial to rebuild. That involves a lot of manual QA and the expertise in actually knowing how everything should work.

That said, give it 6-12 months and I won't be surprised if they can one-shot "create a future-complete clone of Photoshop, make no mistakes"

> Right now, the settled law is that such an LLM reproduction is 100% legal.

Where did you hear that? Because it is 100% untrue and is the opposite of current legal guidance from reputable legal expert

handoflixue OC
There was a major lawsuit about this involving Google vs Java years ago. Copying code might not be legal, but an LLM can use the application, learn how it works, write unit tests around that, and then fill in code that passes those unit tests.

The current fun loophole is to have the LLM decompile the existing code, build unit tests around that, and then have a different LLM model build the code that satisfies those tests.

Either way, you can absolutely get a "clean room" result from an LLM.

Yeah a “properly conducted clean room reimplementation” is legal, not an “LLM reproduction” full stop.

And there’s a huge foot gun here in that many LLMs have been trained on copyrighted code that may include the subject of your reimplementation in some cases, which pose a risk of breaking the clean room.

> the settled law is that such an LLM reproduction is 100% legal.

My understanding was that re-invention without copying any code is legal. But scraping code from the browser and re-using it is not. I'd love to know how that plays in the courts with LLMs, as their entire model comes from copying code as training material, not writing new code from scratch.

handoflixue OC
Sorry to have been unclear - I did mean "clean room". But an LLM can easily jump through the loopholes currently required for that.

Regular humans train on copying code too (Stack Overflow, etc.) so unless they were trained on that specific codebase, I really doubt you have any sort of legal standing. And given how little compensation the authors got when their work got trained on, I wouldn't hold out hope for a big payout even then...