logoalt Hacker News

consumer451 • today at 1:53 AM • 1 reply • view on HN

I get that, but isn't that model dead now? Doesn't this whole drama prove it? Is there any way to protect an SPA from ~"Hey Claude, de-obfuscate this, then clean-room design our app in another session" in 2026 - and then apply better marketing - without even knowing anything about code? Doesn't this apply to all client-side & native code? Gaming companies are very aware of this.. claude + ghidra + bevy is going to kill all IP protection for games. Their attempt to stop this is why there is no more physical media.

As another browser example along the lines of Photopea, ScreenRun is amazing as a true one-time pay, client-side app. I have loved that thing ever since I paid the $50. Such a cool app and model that has no server costs. Whoever made that is also my hero. But aren't those days now over? I guarantee there are >100 ripoffs of it now. Isn't an SPA now just basically open source, in the worst way only?

Meanwhile, Photopea.com only works via a website for normies. It is ad-supported, so given all the work put in, and updates, and the fact that it is web served... wouldn't SSR be a better option? (I hate this reality)

edit: I am allergic to Next, so I have been using Sveltekit since I realized that SPAs are now accidental open source. What have others been using for SSR and why? That is the discussion I would really like to have.


Replies

consumer451 • today at 4:26 AM

OK, I have thought about this more and I realized that I have never worked on compute intensive apps like Photopea, so I am truly ignorant here. I also did only SPAs forever, and I am now only learning about SSR and hydration. I guess if there was a truly server-side rendered Photopea, using React something like React Server Components, it would probably not be supportable by free + ads. It might actually cost at least as much a month as the inspiration of the app.

I guess my point was, how can anyone protect any client-side IP in the modern era?