Many people are asking AI models to take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download.
There exist tens of such repositories on Github. I want my website to be the only source of a stable version of my program Photopea. I even received emails from people complaining about something in Photopea, and it took several emails to figure out that they are not using Photopea.com (so it ruins my reputation a little).
I reported it to Github on the 4th of September 2026: https://www.photopea.com/g/XKoqqIGv
Today, a month later, I received this response:
Thank you for submitting a DMCA takedown notice. We've reviewed the information you've provided, and based on the facts presented to us, we're unable to confirm a violation of 17 U.S. Code § 1201.
What do you think I could do? Do you think I should look for a lawyer to deal with it outside the digital world? I really doubt that a real person ever looked at my report, and they probably send this response automatically to 99% of people.
1. Pay a lawyer or firm that specializes in this sort of thing to play whack a mole for you
2. Accept it as normal losses and ignore it.
Contrary to others claims here, it is not a 500/hour thing to do #1 when dealing with firms that specialize in this. it probably would be if you just hire a random one-off IP lawyer to try and deal with this particular instance.
Trying to deal with it yourself will be increasingly frustrating and time wasting for you. You will also never be able to prevent someone sufficiently motivated from doing stuff like this to your software.
Unless you want to spend your time dealing with those folks instead of building the software, you should hand this part off - it's not a good use of your time, value wise.
Put another way: most companies farm out processing of this sort of request to high volume low cost processing teams. Or AI. Or both. For you this is an important one off. For the person processing it it's one of a hundred tickets they are handling today. You are not going to get very personalized attention and consistency.
I don't claim this is how it should be, etc. I simply claim this is how it realistically is. It would practically require legislative change to have a different thing happen here and while interesting to discuss, that seems outside the scope of your questions, which seemed more practically oriented
The bad guys are winning, because the good guys have no legal recourse. The only practical solution is vigilante justice, but that makes you a bad guy.
In all seriousness, this kind of stuff happens every day: bad guys getting away because the law does not have the ability to do anything. How then is one suppose to trust the law, when there is virtually zero chance of seeing justice?
As a general rule, you can write off what it costs for you to make something, but not what you lose from not being able to sell it.
Which means for physical goods, you write off the cost to make them, and for digital goods, you can similarly usually deduct development cost to make the software.
In neither case can you write off the amount you would have made had it not been stolen/sale had not been lost.
The practical effect is that because physical goods have a per-unit to-make cost, and most digital goods don't, physical goods get written off per-unit-lost and digital goods do not.
At least, this is the most general answer I can give you for that level of general question.
To write something off you have to actually lose the money - writing off is a process to decrease your taxable income by your expenses, unless you're inventing fake expenses (read: performing tax fraud) it doesn't generate a greater amount of money than the expenses.
Second, I am sorry this is happening to you.
Third, based on GitHub's reply, specifically
> we're unable to confirm a violation of 17 U.S. Code § 1201
they took your submission as 17 U.S. Code § 1201 takedown notice. Maybe you specifically stated this. Maybe it was implied. This is likely not what you want and GitHub's response is likely correct. The reason for this is that § 1201 prohibits circumventing a technological measure. The JS you host on your public site, even if obfuscated, very likely does not qualify for this protection. Another detail - the reason it took long (a month later according to your post) is that after the youtube-dl fiasco, they committed to manual review, legal and technical, of every 1201 takedown notice [0].
Fourth, if you believe these copies are sufficiently reproducing your copyrighted work, what you likely want to do is file a standard copyright infringement 17 U.S Code § 512(c) takedown notice. This still goes through the same DMCA report flow but it should result in a less stringent review process and a faster response.
Fifth and finally, consider asking your favorite LLM to get more context around these laws. Good luck!
[0] https://github.blog/news-insights/policy-news-and-insights/s...
1201(a)(3): "As used in this subsection-- to 'circumvent a technological measure' means to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure, without the authority of the copyright owner"
> Do you think I should look for a lawyer to deal with it outside the digital world?
Absolutely. This is a copyright infringement case and there is now an appellate precedent to cite. Gather as much evidence as you can and speak with an IP attorney.
[1] https://www.reuters.com/legal/litigation/unsealed-opinion-sh...
... so virtually no one considers that ruling to be the final word on the topic (sadly).
Remember that there is still quite a bit of friction to doing that, and that many people have better things to do than jump through those hoops.
In addition to the "hire a lawyer" comments in this thread, I suggest building in some heuristics that detect when Photopea is running outside of your domain. They don't need to be "foolproof," but add additional friction to pirating Photopea so that less people will jump through the hoops.
Some historical examples:
- Commercial software in the 1980s and 1990s would burn a hole on the disk, and the software would look for the error when reading that sector.
- Donkey Kong Country would detect that it was pirated by reading the amount of RAM available. (Because SNES backup systems had slightly different runtime properties than the real cartridge.)
More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.
---
Finally, you could consider a business model that relies on server-side functionality for revenue or stickiness, that's hard to replicate merely by pirating the software. (IE, some kind of server-side storage and sharing system.)
If they're using the github.io repo, the web app can be just as accessible as any other site
Today, there is little point in trying to slow down software pirates. At best, adding an arbitrary piracy detection only adds anywhere between mere minutes and a few days to the effort to crack software. This is true absent AI assistance or even a meaningful understanding of ASM outside of logical JMP instructions. The author will likely waste more of their time implementing anti-piracy techniques than a software pirate would figuring out which function call results in the program exiting abruptly. I've yet to encounter a program where a single flipped JE/JNE or NOP couldn't unlock most or all capabilities. This is in spite of various licensing and contextual checks throughout.
It would slow down a pirate more to have a program modify or decompress itself in memory, but that class of techniques is still more trouble than it's worth. Experienced pirates already know how to deal with those traps. The timeout thing you mentioned is clever, but the type of person who knows enough to disassemble software would think to themselves "wtf does it crash after 5 minutes?", immediately investigate, and identify the source of the crash.
Having a license check is the only thing authors of software should bother with. It provides most people a framework to consider whether they should pay for a product. Most people won't download potential malware from a sketchy website if you offer your product at a fair price. Those who either know how to crack apps or refuse to pay will keep doing what they're doing.
tl;dr Don't fool yourselves into thinking you'll outsmart a kid with Ghidra installed by throwing a glorified if-statement in their path.
EDIT: I'm speaking in the general sense. The same principles apply to an app that runs almost all of its logic in the browser.
This is a very frequently repeated point, which is simply not true.
People using pirated versions are perfectly aware of the fact that they are using butchered versions of the original. So when it crashes, the most reasonable explanation is that of a botched DRM bypass. No need to be coy here - it crashes because it's pirated. It's a bloody obvious connection.
As for DMCA filings, we publish all of them here: https://github.com/github/dmca
I see two from Photopea, one from 2022 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) and one from 2024 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) - could you point to the recent filing?
I work at GH, but am not involved in DMCA filings, and can in no way answer or judge this case, but potentially follow up internally.
Github did take down this https://github.com/spooknik/Photopea-Appimage and other repos in the past, but now, I feel like I talk to a robot. I am happy to hear that they have real employee! :D
Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.
I think I will try solving it with a lawyer. But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.
I spent $18k in legal fees over a $22k claim in a construction dispute. I won the suit and was awarded legal fees. So I'm owed $40k plus interest. I've collected exactly $0. The last lawyer I spoke to said I need to cut my losses in legal fees at some point because from a practical standpoint, winning damages isn't the same as collecting them. Especially if the defendant isn't local and has few assets.
The US allows damages per infringement without need to prove an actual loss, and per infringement.
In my experience GH usually does 512(c) takedowns in days; so it taking a month is quite abnormal. OP’s posted response suggests he didn’t file a copyright takedown but rather an anti-circumvention claim; which is a bit special in DMCA law, and generally best avoided when you have merits to do a regular 512(c).
We also don’t have details of the repo. The author has commented on another project that claims to be a LLM _re-implementation_ of Photopea, without directly using source. If that’s the case, it’s entirely understandable why GitHub won’t take it down.
It worked for me! And very quickly.
https://news.ycombinator.com/item?id=49832406
But it is a bit crap that this is the only way you can get Github to behave responsibly.
Good luck.
I think anybody in any line of work or life would like that. It's however unlikely to never run into an issue where a lawyer is really needed, so don't hesitate when you realize you need one.
https://youtu.be/jVkLVRt6c1U
That kind of thing is explicitly required under HN rules - if a company requires payment, it's only OK to post if a “workaround” to avoid paying is available.
Additionally, HN explicitly say it's OK:
* For HN comments to ask how to get around payment requirements, and
* For HN users to help other users to get around payment requirements
Source: Official HN FAQ page
If you don't, don't.
It's that simple. Be an adult, make a choice and live with it.
ETA: I dispute the implication that "honest" software is a category that necessarily excludes all ad-supported software, but that's a side story.
As an aside, I thought that "cracked" software meant software that has had the copy protection or other access control bypassed or removed, not the alteration of the software functionality itself. If your software was actually cracked then you may have some fairly heavy law in your favor. For better or worse, bypassing access controls (even weak or simple access controls) gets special legal attention.
Less than 7 figures (~1 million) per year -- not per month -- based on previous comment from 2021: https://news.ycombinator.com/item?id=26769141
A later 2023 interview updated it to ~$200k/month (~2.4 million/year) : https://web.archive.org/web/20240606073354/https://saastrapp...
(I'd just quit my job if I had an income like this.)
Run the code you want to protect in a cloud function. Cache the user data on the server; modify it on the server, send the diffs to the browser.
</Naive>
<MoreNaive>
Any product that agent can generate from a prompt or reverse engineer will be cloned.
</MoreNaive>
<MostNaive>
Solve problems that make your life better even if cloned.
</MostNaive>
OP, I’m sorry this is happening to you. It must be incredibly frustrating to have people ripping off something you’ve worked on for many years and pass it off as their own work. I would be furious in your position.
I wish I could do something directly to help you but the best I can offer is to echo the best advice others have already given you: it’s time to get a lawyer. That is the one guaranteed route to get GitHub to sit up and take the action they should already have taken on your behalf.
I think we're also going to see the strategy to be to remove the processing and magic sauce from the client and move it to the server where it can't be decompiled and rebuilt with AI.
I'd wager we will start to see more web apps like this have greater obfuscation and dependencies on operating on a particular domain. Sure AI can help to circumvent many things, but at a certain point they pay-off may not be worth the effort.
Also if it could recreate it that would be fine, because it would be doing so without having access to the source.
I find it unlikely that photopea was never scraped for AI training considering they are looking so hard for new material they started buying up and scanning old books.
This doesn't sound that hard to automate these days.
The magic sauce haven't been in the client for many applications for years. Google barely has any application that runs on desktop OS even though they could have released them.
It's a 1-man operation so it may have not have been financially viable to architect the app as server-based.
- server-based : must invest a lot more money in server farms and extra disk storage, or pay high AWS cloud fees. E.g. if a million users do a blur or denoise filter, all that cpu processing has to happen on the servers, and massive disk space to hold the intermediate files, and extra bandwidth costs to send the changed bytes back to the client.
- client-based : just ship Javascript blobs to end users' web browsers because the blur/denoise/etc filters happen on the desktop.
Also, this type of pixel-editing software still needs a ton of client-side Javascript to behave like a Photoshop clone because users want to see interactive changes as they dynamically slide the blur/noise/etc settings. Round-tripping that with extra server latency is not a fluid UI experience.
We can't confidently replay the past and say that starting it as server-side app from the very beginning means he'd have the same $million in revenue today. Instead, the extra server costs and UI jankiness could have doomed the project.
It's a business decision, and I'm not sure if they made the right decision. Most client-only web applications are open source because they know there is no business in selling it as a service. Photopea somehow is an exception, but its business model is getting questionable which is not a surprise at all.
It's also possible to use a combination of cloud based and local computation. Figma is doing quite well in that regard, especially with the use of WebAssembly. No doubt that potentially means more work, and potentially forcing users to create account etc. But hey, that's a business decision as well. If you don't do anything but just keep everything in JavaScript, this was going to happen.
SaaS killed Open Source with it, two decades ago.
Someone can always make a new repo without redistributing your code, sourcing and hot-patching it directly from your domain. GitHub deleting this repo won't ever fix it, you're playing whack-a-mole and doing free PR for these repos here on HN.
We seem to forget that this website is called Hacker News.
Why is it comedic? All of my own code is open source and freely available, but protected by copyright -- namely via the GPL. Copyright is what helps ensure that we retain open code, and ensures that it propagates openly.
How much further along the enshitification path do you think Android would be, if Google wasn't bound by the GPL in so many areas? Copyright with code is not only fair (why on earth would creating code be different to creating anything else?) but it is what keeps so many things free and open.
That may well be, but as long as that concept exists in law, I sure would like every developer to be able to benefit from it equally, not just Microsoft and Adobe.
At the end of the day the fact many people abuse IP laws doesn't mean there are no legitimate uses.
I do not want enshittified software that creates a bogus need for a server in order to extract licensing fees from me. I prefer to pay for locally run software, paying in ad views if I have to because that’s the micropayment system we have ended up with.
So is there a path to an ethical, viable business model for the author?
Yes and no. An ethical business model for software in this world must be built on a long process of collecting good faith from customers, it just doesn't pay well enough compared to the ones that shatter said faith (adware, exploitation, dark patterns). I think the software moat will be more and more based on social capital. People are happy to pay for the software if they know for a fact that company/person behind it isn't being hostile to them. Look at Steam as an example of this. And you can always open source your code, and still make money through the means of good faith. Is it actually viable? I don't know. It depends on how much money you want to make.
The old model of server-locked licensed software is going the way of the dodo pretty fast right now, though people may not realize it if they're not hunting for alternatives to the old guard suites yet.
And while personally I agree with the commenter above you for personal reasons, I also think that the OP is missing that while the people who've ripped their js tool may have done so directly from their site, no one certainly has to any more: they can likely black-box something similar pretty quickly, at which point the author's DMCA moat is gone.
Stopping me from editing out parts I don’t want to run seems odd. If you want me to run certain things, do it on your own hardware.
This reminds me of the arguments against ad blockers. I don’t want people to force me to watch ads and not allow me to block them on my own machine.
That is my preffered business mkdel for software development.
Adverts are likely a poor business model here - if you want to sell to professionals and creatives, the visual look of the software matters. It should really be subscription or one time licence
From my perspective, those people who are taking this public client side code (not emulating any kind of server), and removing the privacy nightmare, are actually doing good for society. The software is more usable, more performant, and far more secure when they are done. The only harm is the authors ability to monetize.
I don't think it's possible to have a fully client-side web product and be able to enforce strict guardrails on the use of the code. Regardless of ethics, it's just not feasible. What you give up by delivering the full source code to the browser to render is control over the source code.
If the author wants more control over their source code, and easier monetization, they should compile a binary and distribute that. The guardrails protecting source code, duplication, and copyright infringement are much more clear. That's just the harsh reality of delivering source code to clients.
.. is something the author should have considered before deciding to publish AdWare.
You had commented on the photocraft post prior, so if it's that, then it's a bit muddled. It's a LLM based re-implementation and not a copy of the code made open. So the argument would be weaker there, and you'd really need specific code samples to make a case of copyright infringement. Photocraft not "piracy" as is normally understood, which is the exact same binary, optionally with the license protection removed.
Right now, the settled law is that such an LLM reproduction is 100% legal.
If you really want to protect your software in the years to come, you might have to seriously consider starting some sort of popular political movement to address this issue in copyright law.
Current models can already do a full reproduction of anything with source code available (e.g. JavaScript...), and there's already been some poor-quality Photoshop knockoffs.
Where did you hear that? Because it is 100% untrue and is the opposite of current legal guidance from reputable legal expert
How so? Interfaces are not copyrightable, but that it not the same as dissecting a js bundle and copying the implementations. Are we sure these LLM are keeping sanitary habits there?
several courts have ruled Ai output is not copyrightable, I am unaware of any co-authored cases
But, the use of LLMs is not disqualifying. To qualify for copyright protection your work simply must have a sufficient degree of human authorship.
However this is just about protection, not infringement.
If you use an LLM to generate something and that LLM just happens to output something that another human wrote, you may be liable for copyright infringement.
Here's an article from Jones Day that confirms what I just said:
https://www.jonesday.com/en/insights/2025/02/copyrightabilit...
Or perhaps the people should admit that copyright, an artificial construct which is not rooted in natural property, was inherently broken and is not (or at least no longer is) a net benefit to the society and simply adapt around it.
I’m personally waiting for LLMs to get so good that I can make music and movies based on my favorite ones. I probably could never release it to the public, but being able to make it and enjoy it myself would be amazing.
Modifying/modding/remixing software was simply not as feasible as music, but LLMs made it possible.
Copyright, patents and IP are the evolution of our (Western) way of converting research into a form of financial investment.
And a big church could employ lots of them, and thereby stimulate the economy. It seems that the Baroque Era and churches crammed to the rafters with art, may be an artifact of a very good job market for those architects, craftsmen and artists!
Yeah... you could copy some sheet music and share it around, but it still required skilled musicians to perform, play and sing it. And nobody was taking photos or uploading JPEGs of your art and sculpture, so it was fairly locked-in that people needed to visit, and see it in context. So it stood to reason that you could probably reconstruct Noah's Ark from the fragments of True Cross that were circulating around Europe... and how many fingers did your favorite saint really have?
Copyright-free church economics have sort of fallen apart since then. However, museums, arena concerts, theaters and the rest, they have all taken pages from the Church playbooks. The fact that a church can still draw in hundreds for a show with great production values, every week or daily, seems dull and unremarkable now, but a good rock concert or museum collection can evoke the same "goin' to church" fervor in people who like that kind of stuff.
I have agents maintaining several patches to my main tools, not forking, not sharing (some have no interest), personal adjustments
There is basically zero pushback to generated code. All the crazy Minecraft in GTA type mods that came out in the last couple weeks are obviously vibe coded but no one cares because they play good and surprisingly bug free.
If he put in AI visuals as in generated textures then it's different, because that's way more visible and gets labeled as slop immediately. There's also the (accurate imo) perception that AI is taking artists jobs against their will but coders adopted it on their own and benefit from it, so using it for code is ethical from a labor rights POV.
Best of luck with the copyright complaint.
Did they actually republish you code or were they just creating wrappers that download/cache the code from your website to run locally?
Hope you manage to get it sorted but I have no idea how that would go down at this point. I’m sure at least one of them could claim they copied it off the other ones and then you’re shit out of luck.
Can't you just steal the entire WASM code just as easily? I mean, I guess if the ads are stuffed in WASM that becomes a problem. But LLMs are pretty good at reverse engineering. I can't imagine it would be too much effort to get them to take the ads out, or to replace your ads with their ads.
If you have one of these, it’s possible that GitHub would honour it if you go via a lawyer.
Hire a copyright lawyer.
Start going after the people that run this as a service, for both copyright and trademark infringement (you have a trademark for photopea right?).
https://github.com/martinwoodward
before starting heavy artillery with lawyers.
(Martin also often posts on HN).
It won't stop AI thieves cold, but now they'll be in violation of two kinds of law unless they do a bunch more work to rip out all the trademarked branding.
Finally, move beyond ads as your business model.
An ad blocker removes the ads from your website, and still leaves you paying to host the traffic. In a way it's worse for you than what unauthorized mirrors are doing. You're seeing that there's unmet demand for what you are offering, so my advice is: figure out how to capture that demand. Why aren't those people taking the deals you're offering them?
I took the liberty of disabling my own ad blocker to do a little research and HOLY COW THESE ARE BAD ADS.
Let's lay out the problems:
- Something is horribly mangled in the ad loading code. The ads flash in and out of existence, and cycle through at breakneck speed, ~5 seconds per ad. Between the flashing in and out and the flashing different ads, it is not possible to do serious work with this going on.
- Many of the people who don't have a photo editor on their device are using touchscreen devices. Many of those people are right handed. For them the actual photo editing tools would be largely impossible to use without accidentally clicking a giant ad which takes up the whole right side of the screen, at which point they would no longer be able to edit photos. Once this happens to you 5 times or so I imagine you start to get very angry.
- Because the ad doesn't fit into the UI at all, you're wasting huge amounts of the screen and impacting productivity proportionately.
So I guess my final advice is: if you don't respect your users, I don't know why you would expect them to respect you. Offer a better deal and more people will take it.
I've seen people on Reddit writing things like, "Come on, what's the big deal? AI can write any code now." I disagree. There are hundreds of thousands of lines of code here, very complex code, which even AI wouldn't be able to write on the first try or in a single day. So this person stole this code from Photopea and built a product on top of it.
You will never sue your way out of this. Piracy will always exist. GitHub will respond to a legal notice but whack a mole is the game and legal notices cost money
The solution in the WP community at the time was variations of the plugin as a loss leader to get revenue with support or to leverage community visibility into larger contracts for work or hosting the platform for others.
If your business model depends on your code being a secret, JavaScript is not a good play. The business model needs to enhance what the code offers since it’s basically a commodity now
My understanding is because of the way PHP works all plugins are directly interacting with the wordpress code.
Commercial plugins are a thing, next.
I've had an AI reproduce astronomical formula functions without difficulty in whatever programming language I want. Graphical algorithms aren't even a challenge.
Might be time to reconsider the business model entirely, because Pandora's box is already opened.
But wow, how do you stand a chance in stopping anyone when your code is all there freely available in the browser
Because it is trained on code of people like Ivan
https://www.reddit.com/r/Bard/comments/1wxmqpt/ive_created_o...
Headspace updated it's privacy policy info recently, which got me to have it checked with an LLM. And it turns out that what you're doing on $100 per year meditation app is still being sold to anyone willing to pay. Using headspace lost it's charm. I wonder if Andy ever agreed to this.
(I only noticed because your site is not blocked in the UK but most of the templates are.)
*They wash their hands of any GDPR deletion/anonymisation requests, instead passing them and your identity documents to the repository owner!
I would not fork or re-release proprietary code. I would ask my LLM to write a very rigorous end to end test suite for your tool, delete all the code, then have a clean context LLM re-write the code to pass all the same tests. Then I could publish it under an open license.
Ads are a cancer, and it is a matter of weeks before someone does the above where you have zero recourse.
I suggest open sourcing the code properly without ads yourself before someone does it for you. If you do that someone might donate to you instead of paying for the tokens to clone your work.
Software is no longer a moat and DMCA means nothing anymore.
A closed source, client-only "desktop" application, especially a web app with obfuscated/minimized JavaScript code, has no real copyright protection these days. You either sell ads, sell it to enterprises, or if you are lucky enough to be able to pull it off, sell a subscription. Not putting the logic on the server in the first place means everything is basically public knowledge.
If ad was the only way to get money, there would be no product/service to sell anymore and thus...nothing to advertise. It just cannot work that way.
Photopea is lucky that it has a decent amount of revenue. But that's an exception, not the norm. Generally speaking, for new software, the business model of desktop, client-only software hasn't worked well since late 2010s at least, and nobody should expect to run a viable business like that today. There are very few applications you "install" on your computer that doesn't require native capabilities in some way.
The real engineering work that will always be paid for is identifying problems and testing solutions to see what solves the problems.
The substrate in which we use to do that will change, but the job will endure.
Those that just do what they are told however, yeah they are SOL unfortunately.
Creative problem solving is the only skill that will matter anymore.
If security is a solved problem then anyone that wants to teach themselves enough can move to trying to solve disease, until disease is solved, then we all move on to building enough robots to mass produce enough food to solve world hunger and shelter... and once the needs of everyone on earth are solved at an ever cheaper price until it is free... then I guess we do whatever we want.
Capitalism is just a bootloader to get us there.
Humans once built things to benefit society over multiple lifespans.
It's not. The economic landscape is also entirely different from before as well.
So you are going to have to prove their code is a copy of yours, not just a copy of the functionality.
In Google vs Oracle, APIs also aren’t necessarily copyright able:
“So long as the specific code used to implement a method is different, anyone is free under the Copyright Act to write his or her own code to carry out exactly the same function or specification of any methods used in the Java API. It does not matter that the declaration or method header lines are identical”
To sum it up; get a lawyer.
This reminds me of LLM companies scraping the entire internet and destroying millions of books to scan them in bulk quickly and then complaining about others performing distillation attacks against their models.
It's fine to be unhappy about people coming to you with complaints about forks of your software, but if the premise of your project is "we made a near perfect clone of Photoshop so you don't have to pay for it", haven't you kinda ethically ceded the right to complain about other people copying your software, even if you managed to stay within the confines of copyright law?
If you're building on other people's ideas and work, don't you owe the world a duty of reciprocity in openness?
Bring back look-and-feel copyrights and the Whelan interpretation of software copyright. Programmers have gotten away with stealing the patterns for entire programs, producing identical clones of another company's valuable IP, for far too long.
I have a feeling that Whelan is going to become relevant again as judges realize that people are using AI to copyright-launder major applications and games (a practice for which I'll coin the term "sloppylefting"), effectively stealing them in a way that cannot be prosecuted using the current very strict interpretation of copyright law with respect to software.
Photopea creator weighs in on Photosuite project
https://news.ycombinator.com/item?id=49972730
Sorry GitHub, that's not for you to determine, as you are not a US judge. They should never have replied like this IMO and this behavior opens them up to liability for not properly handling DMCA procedures.
Proper DMCA 512(h) notices (assuming OP's was proper) require the host (github) to remove or disable the content first without even attempting to verify the claims.
Then the repo owner has a chance to challenge the notice. If they choose to do, they're basically required to publicly doxx themselves first, by nature of just going through the motions of the judicial court system.
If there was no challenge after a set period of time, then the content stays down.
If there was a challenge, it stays down until a court decides what happens next.
two sides to the coin, we'll hear about how some evil corporation used their influence to have a legitimate project DMCA'd and HN will have the opposite reaction on that day
something like "jury duty" from the community seems an interesting idea for a middle path, if we want better systems, we'll all need to contribute a little to making it so
Use a trademark.
Something else is needed. If the code is basically open, then there is no technical protection. Remove tens of those repos - hundreds might appear.
Second, the trademark will help you against the masqueraders, those copying your tool and the Photopea brandmark. That will help with customers complaining about some other modified product. It will not help in case you find someone copying your codebase and putting it out in the open under a different name. For that, you'll need a copyright.
Doing both of these might be expensive but gives you complete legal standing. Companies will have no choice but to take down the copies.
Meanwhile AI refuses to touch photos that contain anything that remotely looks like Mickey Mouse.
Shit was never on the Common Folk's side.
This doesn't lend it self to a sensible solution.
There's no way that computer code should have ever had any legal similarity to entertainment properties like Disney characters.
Plus so many people don't want to pay any attention to the way there's a big difference between entertaining software like games versus things which are needed before "machines" will even (barely?) run, or run more superbly which is not the same either.
And there's no way any "rights" should exist for an extended period.
Among other things these need to be corrected more so than ever (or AI will do it for us). The problem is it all needs to be sensibly reversed not gutted in one big shockwave. But AI is here to shock. It doesn't even take superintelligence, if the people who gradually caused the problem over the decades were below-average things would have come out better as long as their objectives were less predatory.
My reply is that you now own a customer list, brandname and trademark, and that is about it.
I would imagine they all converge on common features and core implementation foundation
This day in age, we need to verify ourselves
Can you show us an example? How did you verify?
I wanted to discuss the behaviour of Github without giving these "projects" even more attention.
I would think a github link would be easy to provide, sus that it hasn't been
This smells a lot like the Laya thing to me, especially with the astroturfing by friends and fans
Because if the javascript source matches the source in the repo, then they copied it
If you want to make proprietary software that's cool, but client-side JavaScript was a terrible choice. The cat is out of the bag.
There's a reason software for which you purchase a license key generally doesn't give you source code outside rock-solid legal agreements.
Because what I see is essentially "they're storing stolen property" but the burden of proof is on the author to prove it was, indeed, stolen.
I imagine the bar for that is pretty high otherwise anyone could weaponize DMCA to target their competitors' repositories.
That's not what OP alleges - they are saying people are redistributing modified versions of OP's copyrighted code. DMCA is an appropriate measure in such a situation, but it's unclear why OP's DMCA takedown was rejected by GitHub. Without more detail, it's hard to comment further
https://reclaimthenet.org/kiwi-farms-dmca-subpoena-anonymous...
That is an extremely disingenuous and bad faith interpretation of what OP has said and I think you know it. You want to be edgy? Go comment on Reddit.
OP is rightly frustrated that their copyrighted work, that they’ve been working on full time for over a decade, is simply being ripped off by people and GitHub refuses to do anything about it.
Shifting blame to GitHub is absolutely idiotic.
Try removing locks from your doors in a high crime area (which is what the Internet is) then being indignant when the police can't stop all the criminals stealing your property.
> take the Javascript code from my website, remove all ads from it
I would assume that this might be one of the reasons why people are modifying and repackaging your product. I would suggest to remove that incentive. So that the people will have no reason to repackage your product because it has annoying features. And so that they could use it directly and be happy about it.
Arguably Photopea made a mistake, and now they are paying for it.
They can fight, but it's a losing battle.
I think that the differentiating factor must be something else than the software product feature. Because that can easily be copied or recreated.
It can be e.g. the customer support where customers will be listened to and will have their suggestions and requests implemented as features.
No one implied that the author should offer their product for free. I merely suggested that they need to focus on other aspect of their product rather than the mechanical software parts because they can no longer be the differentiating factor. Precisely because they could easily be recreated or copied.
I say that as someone who thinks about this almost every day.
Do you have any concrete ideas for how to do this or are you just saying this to defend piracy?
Wonder how many even built a popular free product supported by ads?
It's quite difficult and you need to provide even more value than a paid product (if that makes sense) for users to come back constantly.
There is nothing new now with people copying software. It's just that much MORE of the masses have access to this now than before.
And thus thieves multiply exponentially.