Tell HN: GitHub refuses to remove cracked copies of my software after a month

Tell HN: GitHub refuses to remove cracked copies of my software after a month

31 pointsby IvanK_net79 comments

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Man, some of the comments this is getting are absolutely wild.

    OP, I’m sorry this is happening to you. It must be incredibly frustrating to have people ripping off something you’ve worked on for many years and pass it off as their own work. I would be furious in your position.

    I wish I could do something directly to help you but the best I can offer is to echo the best advice others have already given you: it’s time to get a lawyer. That is the one guaranteed route to get GitHub to sit up and take the action they should already have taken on your behalf.

  • The 3rd U.S. Circuit Court of Appeals recently ruled [1] that using AI to train on a competitor's copyrighted material to build a competing product is _not_ fair use. This is a recent ruling (September 30, 2026). GitHub policy has surely not caught up yet and who knows when it will.

    > Do you think I should look for a lawyer to deal with it outside the digital world?

    Absolutely. This is a copyright infringement case and there is now an appellate precedent to cite. Gather as much evidence as you can and speak with an IP attorney.

    [1] https://www.reuters.com/legal/litigation/unsealed-opinion-sh...

    by hgs3
  • You should discuss this with an attorney that is experienced with IP law to see what your options really are. IP law is very complex and sometimes very surprising. You need expert legal advice, not advice from the HN crowd.

    As an aside, I thought that "cracked" software meant software that has had the copy protection or other access control bypassed or removed, not the alteration of the software functionality itself. If your software was actually cracked then you may have some fairly heavy law in your favor. For better or worse, bypassing access controls (even weak or simple access controls) gets special legal attention.

  • Hey guys, thank you all very much for your comments! I just woke up, I did not really believe my post would get this much attention, so thanks!

    Honestly, I was a hoping that giving attention to this problem here at HN might lead to someone from Github actually noticing my problem and looking into it.

    I think I will try solving it with a lawyer. But it would be really cool if I could spend my days writing code instead of dealing with lawyers and stuff.

  • Is there a ticket code or other contact you've been in touch with?

    As for DMCA filings, we publish all of them here: https://github.com/github/dmca

    I see two from Photopea, one from 2022 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) and one from 2024 (https://github.com/github/dmca/blob/d97814f268e07e62aabe8b5c...) - could you point to the recent filing?

    I work at GH, but am not involved in DMCA filings, and can in no way answer or judge this case, but potentially follow up internally.

  • > take the Javascript code from my website, remove all ads from it, and they publish such a "new product" on Github for everyone to download

    Remember that there is still quite a bit of friction to doing that, and that many people have better things to do than jump through those hoops.

    In addition to the "hire a lawyer" comments in this thread, I suggest building in some heuristics that detect when Photopea is running outside of your domain. They don't need to be "foolproof," but add additional friction to pirating Photopea so that less people will jump through the hoops.

    Some historical examples:

    - Commercial software in the 1980s and 1990s would burn a hole on the disk, and the software would look for the error when reading that sector.

    - Donkey Kong Country would detect that it was pirated by reading the amount of RAM available. (Because SNES backup systems had slightly different runtime properties than the real cartridge.)

    More importantly, when detecting that Photopea is pirated, if it runs for 3-6 minutes and then crashes, it's more likely to look like a bug in the export than a deliberate anti-piracy attempt.

    ---

    Finally, you could consider a business model that relies on server-side functionality for revenue or stickiness, that's hard to replicate merely by pirating the software. (IE, some kind of server-side storage and sharing system.)

  • First off, let me get this out of the way - I am not a lawyer. If you want a legal advice talk to a lawyer.

    Second, I am sorry this is happening to you.

    Third, based on GitHub's reply, specifically

    > we're unable to confirm a violation of 17 U.S. Code § 1201

    they took your submission as 17 U.S. Code § 1201 takedown notice. Maybe you specifically stated this. Maybe it was implied. This is likely not what you want and GitHub's response is likely correct. The reason for this is that § 1201 prohibits circumventing a technological measure. The JS you host on your public site, even if obfuscated, very likely does not qualify for this protection. Another detail - the reason it took long (a month later according to your post) is that after the youtube-dl fiasco, they committed to manual review, legal and technical, of every 1201 takedown notice [0].

    Fourth, if you believe these copies are sufficiently reproducing your copyrighted work, what you likely want to do is file a standard copyright infringement 17 U.S Code § 512(c) takedown notice. This still goes through the same DMCA report flow but it should result in a less stringent review process and a faster response.

    Fifth and finally, consider asking your favorite LLM to get more context around these laws. Good luck!

    [0] https://github.blog/news-insights/policy-news-and-insights/s...

  • IP lawyer here - I can't give you actual legal advice because you aren't my client, but generally, you have two options here, neither of which will be surprising, or very satisfying:

    1. Pay a lawyer or firm that specializes in this sort of thing to play whack a mole for you

    2. Accept it as normal losses and ignore it.

    Contrary to others claims here, it is not a 500/hour thing to do #1 when dealing with firms that specialize in this. it probably would be if you just hire a random one-off IP lawyer to try and deal with this particular instance.

    Trying to deal with it yourself will be increasingly frustrating and time wasting for you. You will also never be able to prevent someone sufficiently motivated from doing stuff like this to your software.

    Unless you want to spend your time dealing with those folks instead of building the software, you should hand this part off - it's not a good use of your time, value wise.

    Put another way: most companies farm out processing of this sort of request to high volume low cost processing teams. Or AI. Or both. For you this is an important one off. For the person processing it it's one of a hundred tickets they are handling today. You are not going to get very personalized attention and consistency.

    I don't claim this is how it should be, etc. I simply claim this is how it realistically is. It would practically require legislative change to have a different thing happen here and while interesting to discuss, that seems outside the scope of your questions, which seemed more practically oriented

Explore Birbla archives