Hey guys, I am the creator of Photopea, I just woke up! I did not expect that it will blow up like this.
Thank you all for your support! Many repositories like this one exist on GitHub, I tried to report in in the past, but I was completely ignored by Github / Microsoft. I feel pretty powerless here :( I tried to call them out publicly - https://x.com/photopeacom/status/2106877355738140875
This "PhotoSuite" thing got me a bit angry, since the author presented it as an original work, when I clearly see that such a project can be made from my "pp.js" file in two hours using Claude. Also, I believe that their README.md did not mention Photopea before I wrote my first comment there.
Thousands of people shared "PhotoSuite" on social media and nobody minded the fact that they don't know who the creator is. The creator is still offering it on their website as their original work: https://www.photosuite.app/
We live in interesting times. AI can (or will be able to) de-obfuscate every bit of code that was ever published, convert binaries to readable C++ and so on. So, in theory, AI models will train on the source code that we consider "closed-source" now, and will be able to recreate this software if asked. But it wouldn't be possible if a real person did not spend thousands of hours of their life to write that software years sooner.
I have always been excided to see people make AI create something new, what didn't exist before. But so far, I mostly saw only "approximations" of expensive software, when AI tries to recreate each feature and each button according to what it thinks it should do, or "forks", when AI takes the full code of something and tries to "bend" it to hide the similarity with the original work.
It feels like we need to be more and more vigilant about relying on tools from these big technology companies. Especially if you are running a small business. They really don't give a shit about you unless you have enough pull to get on the front page of HN.
There's no evidence the PhotoPea author ever decompiled PhotoShop binaries. He emulated a desktop program's functions, menu structure and look in a web app by writing original code. Even if you had the PS source code, delivering a PhotoShop-like experience in a web page requires a lot of original work (especially in 2013). Before PhotoPea, Adobe had said that making PhotoShop browser-based would be extremely difficult, if not impossible and never be performant.
PhotoPea proved that with enough work and skill it was possible. Having an LLM coding agent look at PhotoPea itself and turn it into a copy of PhotoPea and then representing it as your own work is not at all the same.
Yes, and I totally support it! They start "from zero" and build everything piece by piece by testing the input / output of each feature. I just hope they use Photoshop / Photopea / Other software only from the users perspective and not by analyzing the code (source code or "binaries" - it probably does not matter to AI nowadays).
In this case, it was a clear copy-paste of my code, whith the variable names changed by the AI.
I use photopea every day. I can only imagine the complex emotions you're going through. I am not nearly as attached to my software, I imagine, just because of how "unimportant" it is.
I am still very attached to it though. For no good reason other than "it's mine", I think.
Isn't it a good thing software can't be closed? We have to use someone's tool though, and ego is inevitable, so idk? 100s of separate "open source" versions and people use what they think is the best?
Is it just about accountability? and having an author/human attached to the product to direct it? Choosing the person you have the most faith in?
If your answer to "here is an example of 1:1 copying of my code and I can do the same for every line in your app" (Github comment 7, from the Photopea author) is to copy/paste a justification from an LLM (comment 8, from the Photosuite author), you've lost the argument.
The hard reality though is any site written in JavaScript is now part of an LLM's training set and can (and will be) be trivially rewritten into something new. Interesting times.
>“He who hath grown wise concerning old origins, lo, he will at last seek after the fountains of the future and new origins. […] For the earthquake—it choketh up many wells, it causeth much languishing: but it bringeth also to light inner powers and secrets. The earthquake discloseth new fountains.”
How bizarre. The thief has already deleted the thread. So obviously guilty just by the fact that it's clearly a browser app inside a desktop wrapper. That makes absolutely no sense as an architecture decision. And it uses all of Photopea's libraries. Before the thread was deleted, they had spawned a few sub‑agents to come in and bully the Photopea creator. But none of it was believable; it was clearly an angry thief lashing out.
That makes absolutely no sense as an architecture decision.
It makes a lot of sense architecturally. It's much simpler to update a webpage than force every user to update their app when something needs to change. Consequently a lot of apps, especially on mobile, use a system webview with a page loaded from a server and rendered to look like the app for anything that gets regular updates. The alternative is having lots of versions of the page and needing to manage all the different variations of payloads from them.
Backwards compatibility in an API isn't that hard, but when there's a simpler option (a webview) people will take it.
That said, if there's no native stuff in the app, it is a bit harder to justify.
> It's much simpler to update a webpage than force every user to update their app when something needs to change.
The capabilities available to native desktop apps is a superset of the capabilities available to browser-based Web apps.* Ergo, if browser-based app distribution offers some desirable quality, the same path is available** to a native app not built on W3C/WHATWG APIs.
* You see people make a similar logical error when it comes to being more distrusting of browser-based apps than native binaries, especially putting undue focus on the risk of the app exfiltrating your data over the network, even though a native binary can do strictly more damage (i.e. all that and more, like doing the equivalent of rm -rf on your home directory).
** It does require, though, that one actually take that path.
That's all wonderful until some dipshit decides to cut features because they were too much of a maintenance burden. At least with the desktop app you can push back and not update.
There is zero chance the author of that issue read their own post.
The vast majority of license violations are just MIT or ASL projects whose license text got stripped in the minified deliverable. Just adding source maps for those libraries is enough to become compliant.
I have no clue with regards to LGPL on the web but since it is delivered via WASM, there is a linking boundary so it might just be an issue regarding letting users bring their own implementation.
From another OSS author: Just let it blow over. Don‘t engage. Ignore it. You‘re already making a mistake justifying yourself to people you‘ll never convince. Leave, for a time.
All I know for sure is that the author of Photopea is not AI and I remember when he first released it. No one was calling it a photoshop ripoff. People were calling it an actual open source alternative that functioned and didn't cost the heap of cash Adobe wanted. I recall the response to the announcement being quite positive.
Can confirm he is not AI and he also used to hang around here. Also before photopea, he tried to make a living once with a open source project, a flash replacement graphic libary for the web, called IvanK.
So that did not work out, but I used it a bit and interacted with him couple of times there, before moving on to easel and later pixi, after it became clear it would not take off and the other ones had more support.
Glad for him to found success with Photopea later, and he definitely has my sympathy here.
But I doubt this will work out much longer in the long run. It is just too easy cloning and improving projects with AI.
I find Photopea to be completely legitimate, and ripoff is too strong, but you can recognize that it's not just a "fairly feature-comparable alternative". It has most of the functionality at the exact same place, with the exact same shapes, because that will help user if they already know how to work with Photoshop. That makes Photopea a well-executed clone, one that has been reimplemented on another platform from scratch.
Why not just apologize and have Claude rewrite any code that's similar? Whether you did it intentionally or not, you probably agree that you can't keep using his code and that it would pretty bad if someone did something similar to you.
I mean, it seems a pretty open-and-shut case. The author literally admits he copied the code. From one of the comments he makes:
> @kuckir, to be clear about the lineage: PhotoSuite started from the Photopea build mirrored at https://github.com/ruanjiyang/Photopea-Offline, and the README credits Photopea as the primary inspiration and prior art. Over the past year it's been rewritten and rearchitected module by module, retargeted for desktop, restructured into ~330 source files, with a lot of features Photopea doesn't have. It's a rewrite of that lineage.
That Photopea-Offline is an unofficial rip of the actual app. Pretty sure using a pirated version doesn't suddenly grant you license rights to use & extend the code into another competing product...
Absolutely. There’s a lot of this going around on twitter too with all the game reverse engineering with all the AI grifters claiming games are all open source now etc. Yeah right, I don’t think they understand the concept of open source or copyright!
to banning photopea, to when photopea responds with a 2nd account re: some duplicate code which is very hard to explain w/o being, well, duplicated to what you pasted above.
Isn't this a pretty obvious case I mean the author is not even hiding it just check the readme. They found illegally extracted photopea code then used AI to copy it. How are there any doubts on this?
You’ve tried them out? I’m intrigued but haven’t had a chance to sit down and give them a shot. I’m particularly interested in how the vector one performs and how well it works.
We need much more of these type of direct call outs! Shed light on the AI grifters so the community knows what projects to avoid like the plague.
It's embarrassing to be honest. The eolix guy couldn't even respond to the very first piece of evidence by the Photopea creator, before spewing some clearly and poorly generated, LLM response. So of course he'd resort to issue-closing, title-changing, banning, bullying and then Whatabout-ism.
Beautiful rainbow of moral failures...
Goodluck with that "internal audit" buddy. The internet never forgets.
A side note: I wonder what pre-Microsoft Github would do in such cases. I don't think I've ever seen modern Github take action against any clone repo with legitimate copyright issues.
photosuite maintainers could just have ai adjust the code "In the style of X" and get around any argument if copy/piracy. The laws haven't caught up here. I can't imagine how anything could be enforced. Also there's cleanroom as a service :shrug: open source software effectively has no license for someone with tokens to spare.
I don't like it but thats the situation on the ground IMO
seeing what has been happening in the game modding communitiy, with people reverse engineering full rust rewrites of games like modern warfare 2 [1][2], or reverse engineering mashups with cod, minecraft, and skate 3 [3][4][5], the only defence against reverse-engineering literally all software will be to serve it from the cloud, and even that will not be enough. these people aren't even programmers, claude code just downloads ghidra and builds this stuff.
the future of software is oss. unless governments lock down access to these tools to prevent this kind of reverse engineering. which is a horrible future to envision.
I saw someone say that we're going to go back to a situation like the 70s where software is technically copyrightable but there's no reason to bother. Maybe Stallman's dream will finally come true.
To make sure that AI never uses your work (source code or binaries) for training, I see two possible solutions:
- the software would run only on your own server and clients will access it remotely through an interface
- you will sell the software together with the hardware and a proprietary operating system, which does not allow anyone to get the ones and zeros of your software
So, the only way to prevent GTA6 being "decompiled" and "forked" by AI models is to run it remotely (with a video interface), or sell it together with a proprietary console :D
It isn't true ownership if you depend on an LLM you don't own to modify the code in ways you don't understand. That's just proprietary software with extra steps.
By that standard, couldn't I say you don't truly own open source software like Chromium or OpenSSL because very few are capable of understanding the codebase well enough to implement changes?
I think GTA6 will be the real test for how capable these agents are. Some of these mods use well-known emulation methods, and some of these binaries have probably been ingested by the LLM numerous times.
I don't mean to discredit LLM capabilities, it's just that these examples are heavily favored by what's already documented online.
I'm currently working on OpenBFME[0] and I can assure you, enough LLM power guessing at the code in the binaries is enough to get the code for anything
Wine-style PS5 emulation has advanced far enough that I would bet money on there being a pirated GTA6 PC release based on the PS5 version available within six months.
LLMs have changed the obstacle of doing something from (time, attention, expertise) to (time, attention, tokens).
I don't see what's unique about GTA6. It's just larger in scope if you wanted to decompile or greenfield a custom engine.
But at the end of the day you'll be able to unpack the assets yourself and immediately have the worldmap running in a browser in Three.js. And once you're there, you can vibe-code any game you want on top of it.
yeah for sure, and more modern games will probably be more difficult as well. but even so, games feel like one of the harder things to reverse engineer compared to most business software. yes there is the backend component, but that's mostly just crud.
I just find it surprising that the author is complaining about "stolen code" while having been piggybacking (and earning money) from unattributed OSS code for years... https://github.com/photopea/photopea/issues/9042
Half of these are extremely permissive license attribution issues. Seems rather tame, no?
> 4.4. Paper.js (ext1790438722.js)
> Upstream Project: Paper.js (by Jürg Lehni & Jonathan Puckey)
> License: MIT License
> Specific Violations:
MIT Condition: The MIT License mandates: "The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software."
The entire ~200 KB Paper.js library is embedded in minified form with all author names, copyright notices, and license text stripped.
I question the seriousness of the author of "Photosuite". Who goes through the trouble of creating accounts to prove poorly, that they "didn't steal code".
I have no affiliation with anyone in this drama. I heard of Photopea before but never used it. I just opened it to check for attributions and did not find any at all. So if the - possibly fueled by lower motives - accusations about OSS license violations are indeed true, IMO Photopea lost any right to complain about people copying their product.
Thank you all for your support! Many repositories like this one exist on GitHub, I tried to report in in the past, but I was completely ignored by Github / Microsoft. I feel pretty powerless here :( I tried to call them out publicly - https://x.com/photopeacom/status/2106877355738140875
This "PhotoSuite" thing got me a bit angry, since the author presented it as an original work, when I clearly see that such a project can be made from my "pp.js" file in two hours using Claude. Also, I believe that their README.md did not mention Photopea before I wrote my first comment there.
Thousands of people shared "PhotoSuite" on social media and nobody minded the fact that they don't know who the creator is. The creator is still offering it on their website as their original work: https://www.photosuite.app/
We live in interesting times. AI can (or will be able to) de-obfuscate every bit of code that was ever published, convert binaries to readable C++ and so on. So, in theory, AI models will train on the source code that we consider "closed-source" now, and will be able to recreate this software if asked. But it wouldn't be possible if a real person did not spend thousands of hours of their life to write that software years sooner.
I have always been excided to see people make AI create something new, what didn't exist before. But so far, I mostly saw only "approximations" of expensive software, when AI tries to recreate each feature and each button according to what it thinks it should do, or "forks", when AI takes the full code of something and tries to "bend" it to hide the similarity with the original work.
This is the second time we have heard this complaint in the last week. Previously it was https://news.ycombinator.com/item?id=49832406
It feels like we need to be more and more vigilant about relying on tools from these big technology companies. Especially if you are running a small business. They really don't give a shit about you unless you have enough pull to get on the front page of HN.
Genuine question: isn't this what photopea did to photoshop?
There's no evidence the PhotoPea author ever decompiled PhotoShop binaries. He emulated a desktop program's functions, menu structure and look in a web app by writing original code. Even if you had the PS source code, delivering a PhotoShop-like experience in a web page requires a lot of original work (especially in 2013). Before PhotoPea, Adobe had said that making PhotoShop browser-based would be extremely difficult, if not impossible and never be performant.
PhotoPea proved that with enough work and skill it was possible. Having an LLM coding agent look at PhotoPea itself and turn it into a copy of PhotoPea and then representing it as your own work is not at all the same.
In this case, it was a clear copy-paste of my code, whith the variable names changed by the AI.
I am still very attached to it though. For no good reason other than "it's mine", I think.
Isn't it a good thing software can't be closed? We have to use someone's tool though, and ego is inevitable, so idk? 100s of separate "open source" versions and people use what they think is the best?
Is it just about accountability? and having an author/human attached to the product to direct it? Choosing the person you have the most faith in?
/rambling
The hard reality though is any site written in JavaScript is now part of an LLM's training set and can (and will be) be trivially rewritten into something new. Interesting times.
>“He who hath grown wise concerning old origins, lo, he will at last seek after the fountains of the future and new origins. […] For the earthquake—it choketh up many wells, it causeth much languishing: but it bringeth also to light inner powers and secrets. The earthquake discloseth new fountains.”
— Nietzsche, Thus Spake Zarathustra
> the reader emits the model's shape rather than the file's
Oh hello Claude
> the writer derives its field count from Object.keys().length while skipping the sentinel
It makes a lot of sense architecturally. It's much simpler to update a webpage than force every user to update their app when something needs to change. Consequently a lot of apps, especially on mobile, use a system webview with a page loaded from a server and rendered to look like the app for anything that gets regular updates. The alternative is having lots of versions of the page and needing to manage all the different variations of payloads from them.
Backwards compatibility in an API isn't that hard, but when there's a simpler option (a webview) people will take it.
That said, if there's no native stuff in the app, it is a bit harder to justify.
The capabilities available to native desktop apps is a superset of the capabilities available to browser-based Web apps.* Ergo, if browser-based app distribution offers some desirable quality, the same path is available** to a native app not built on W3C/WHATWG APIs.
* You see people make a similar logical error when it comes to being more distrusting of browser-based apps than native binaries, especially putting undue focus on the risk of the app exfiltrating your data over the network, even though a native binary can do strictly more damage (i.e. all that and more, like doing the equivalent of rm -rf on your home directory).
** It does require, though, that one actually take that path.
This kind of thinking is what brought us the trend of painful Electron apps like Teams.
I'll do a code audit (and you should too, before casting stones). The code is there.
https://github.com/photopea/photopea/issues/9042
This is childish behavior.
The vast majority of license violations are just MIT or ASL projects whose license text got stripped in the minified deliverable. Just adding source maps for those libraries is enough to become compliant.
I have no clue with regards to LGPL on the web but since it is delivered via WASM, there is a linking boundary so it might just be an issue regarding letting users bring their own implementation.
The only credit he gave was saying the original project was inspiration.
Then he deleted and banned the original author posting proof that it was a rip of and not just inspiration.
So I welcome him leaving and reconsidering.
> There are people on both sides of the fence, and I want out.
Victim card. How classy. You are using every trick in the book, one by one
So that did not work out, but I used it a bit and interacted with him couple of times there, before moving on to easel and later pixi, after it became clear it would not take off and the other ones had more support.
Glad for him to found success with Photopea later, and he definitely has my sympathy here.
But I doubt this will work out much longer in the long run. It is just too easy cloning and improving projects with AI.
That's a dangerous word. Did you mean adding more features?
Photopea is not, and has never been open source, AFAIK.
A rip off would be using the actual Photoshop source code.
I suspect we're dealing with a child here with a cloud code subscription who isn't quite familiar with US copyright law or software licenses yet.
Archived at: https://web.archive.org/web/20261006025310/https://github.co...
He's the definition of the word "bootlicker".
"But he admitted to killing him, he's innocent!"
> @kuckir, to be clear about the lineage: PhotoSuite started from the Photopea build mirrored at https://github.com/ruanjiyang/Photopea-Offline, and the README credits Photopea as the primary inspiration and prior art. Over the past year it's been rewritten and rearchitected module by module, retargeted for desktop, restructured into ~330 source files, with a lot of features Photopea doesn't have. It's a rewrite of that lineage.
That Photopea-Offline is an unofficial rip of the actual app. Pretty sure using a pirated version doesn't suddenly grant you license rights to use & extend the code into another competing product...
> That's a bold accusation. Would you care proving which bits of the code are "stolen"?
https://github.com/eolix/photosuite/issues/77#issuecomment-5...
to banning photopea, to when photopea responds with a 2nd account re: some duplicate code which is very hard to explain w/o being, well, duplicated to what you pasted above.
edit: it's not, the reddit post https://www.reddit.com/r/Bard/comments/1wxmqpt/ive_created_o...
and github repositories
https://github.com/storytold/photocraft (Photoshop)
https://github.com/storytold/vectorcraft (Illustrator)
https://github.com/storytold/filmcraft (Premiere)
https://github.com/storytold/lightcraft (Lightroom)
https://github.com/storytold/printcraft (Acrobat Pro)
https://github.com/storytold/effectcraft (After Effects)
https://github.com/storytold/designcraft (InDesign)
It's embarrassing to be honest. The eolix guy couldn't even respond to the very first piece of evidence by the Photopea creator, before spewing some clearly and poorly generated, LLM response. So of course he'd resort to issue-closing, title-changing, banning, bullying and then Whatabout-ism.
Beautiful rainbow of moral failures...
Goodluck with that "internal audit" buddy. The internet never forgets.
A side note: I wonder what pre-Microsoft Github would do in such cases. I don't think I've ever seen modern Github take action against any clone repo with legitimate copyright issues.
I don't like it but thats the situation on the ground IMO
https://github.com/eolix/photosuite/issues/77
the future of software is oss. unless governments lock down access to these tools to prevent this kind of reverse engineering. which is a horrible future to envision.
[1] https://github.com/vladtrc/iw4L
[2] https://www.youtube.com/watch?v=9UbADrcEW5w
[3] https://github.com/chasmlol/2010-rust-rewrite-mashup
[4] https://www.reddit.com/r/bevy/comments/1wuu7bx/are_you_seein...
[5] https://www.reddit.com/r/bevy/comments/1wuag9d/skate_3_was_r...
- the software would run only on your own server and clients will access it remotely through an interface
- you will sell the software together with the hardware and a proprietary operating system, which does not allow anyone to get the ones and zeros of your software
So, the only way to prevent GTA6 being "decompiled" and "forked" by AI models is to run it remotely (with a video interface), or sell it together with a proprietary console :D
not to mention there are alternative revenue sources anyways.
By that standard, couldn't I say you don't truly own open source software like Chromium or OpenSSL because very few are capable of understanding the codebase well enough to implement changes?
I don't mean to discredit LLM capabilities, it's just that these examples are heavily favored by what's already documented online.
[0] https://github.com/Open-BFME/
btw this is the actual solution, not that whole stop killing games movement. not regulation.
I don't see what's unique about GTA6. It's just larger in scope if you wanted to decompile or greenfield a custom engine.
But at the end of the day you'll be able to unpack the assets yourself and immediately have the worldmap running in a browser in Three.js. And once you're there, you can vibe-code any game you want on top of it.
> 4.4. Paper.js (ext1790438722.js)
> Upstream Project: Paper.js (by Jürg Lehni & Jonathan Puckey)
> License: MIT License
> Specific Violations: MIT Condition: The MIT License mandates: "The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software." The entire ~200 KB Paper.js library is embedded in minified form with all author names, copyright notices, and license text stripped.
I question the seriousness of the author of "Photosuite". Who goes through the trouble of creating accounts to prove poorly, that they "didn't steal code".
Or rather created it and eolix is your other alias?