I wonder if this is why I've seen a lot videos popping up on my youtube feed related to vibe coded clones of various commercial apps in the past few days. Everything from clones of flagship products from Adob to Microsoft Office.
I built a from scratch rust RAW processing engine similar to the brains behind photoshop and lightroom - its much more powerful and its not even complete yet
Using REA for something as high profile as what we're doing is likely to result in lawsuits. We're doing everything we can by the books.
We cannot look at Adobe sources. Use of Ghidra is disallowed.
REA is probably great for personal apps and for abandonware, but I think if you publish the results and it's found to have decompiled the original proprietary sources in discovery, you might be in for a bad time.
Probably not, there's relatively little secret sauce to something like Photoshop. It's just a lot of grungy work that, I guess, you can now delegate to an agent if you have enough money and time.
As an aside, I've heard a lot of hot takes about how this is the end of Adobe, but I'm pretty sure it misses the point. The main reason people pay Adobe is because it's a familiar line of stable, well-supported, interoperable, and actively-developed products. There's already plenty of cheaper or free alternatives (Davinci Resolve for video, Capture One / Darktable for raw, Affinity for photo editing and vector drawing, etc), and if Adobe survived that, I sincerely doubt they're going to lose pro customers to a vibecoded app where half the stuff is probably subtly broken or left as a TODO, and that will be abandoned in a week, because the whole point was to get that 1M YouTube views.
> that will be abandoned in a week, because the whole point was to get that 1M YouTube views.
Longbets 1 week, haha.
We're working our asses off on this.
Most of the team are artists who use these tools actively and we want the replacements for ourselves. I'm a filmmaker, so you can imagine my frustration of being bitten by the "unsubscribe fee".
I love such work. I hope to roll it into a package that anyone can use in the future. This work is only going to get more important because frontier models getting locked down will make this a lot harder over time.
For example, I use Claude as a bouncing wall for my thoughts and I pointed out that,
> GLM 5.2 was the only thing that helped HF while the agents were trying to access them. The "guardrails" stopped them from doing good. The Computer Fraud and Abuse Act exists. Courts exist. And computers and an internet connection have existed for a long time. There's also 17 USC 1201 provisions with the 1201 a 1 exemptions [Image #31] so in this case, a farmer should be able to work with you to access the tractor they own. Or... IDK... a kindle that's out of date? :) What is lawful and what isn't is rooted not within the act but within intent, purpose and mens rea. And this is something the law has been deciding for centuries now. At one end, your maker can't say that governments should decide while at the other end explicitly refusing to allow governments to be the ones who decide.
This was rejected for "Safety,"
> Opus 5.5's safeguards flagged this session. You may be seeing this for the first time on an Opus model: Opus 5.5 is more capable and has stronger safeguards as a result, which can sometimes flag non-cybersecurity work. We're improving these safeguards to reduce the amount of incorrectly flagged messages. Edit and retry, or continue with Opus 4.8. Send feedback with /feedback or learn more: https://support.claude.com/en/articles/8106465
>
> Details: "[cyber]'
Note, the image here was the Library of Congress' page on DMCA exceptions.
Fundamentally, the idea that you can't reverse engineer things, make things, learn about biology or physics without permission is strange to me. These machines have been trained on the sum intellectual output of humanity, the global intellectual commons, and are being used to close off that commons?
I would be OK with their right to create such restrictions if they weren't lobbying the Government to restrict others, thereby ensuring that they control humanity's intellectual commons well into the future.
Perhaps I'm naive, but I think it's better for humans and the machines if we can all think, learn and build. But then again, I'm the kind of person who rejects the doomer pill.
I wanted to see if CVP approval changed this response, but it appears that with the release of Opus 5.5, Anthropic silently dropped me from the program, and has some strict new criteria in place to apply again, such as being credited for a CVE! I was only approved last month, too -- sad!
I have CVP with the new program (including mythos access) and still get constant denials for silly situations. Most recently I fed a URL to my agent from a security blog and asked if to add it to my obsidian vault with appropriate tags-- cyber flagged. You're not missing much. OpenAI and/or most Chinese models are much more lax in their restrictions.
This kills the talent pipeline, and it'll create a spam problem for the CVE folks because now people will try to github PR spam their way to getting on a CVE.
It's worth talking about the fact that you can't even talk about DMCA to a model trained on the Library of Congress unless you're one of the approved people. And that's before reverse engineering something or writing code.
So in this future, it sucks to be you if you're someone trying to make your small app more secure, someone trying to upskill, a tinkerer trying to bypass corporate lockdowns for a device they own (a recognized DMCA exception, btw), a teenager trying to learn about security...
It locks away much of the richness that produced hacker culture behind glass. You can look at their press announcements and PR pieces, but you can't touch.
And as they're lobbying the government for "sensible regulation," this inevitably leads to a future where computing is controlled.
It's the direction their existing reports are taking. They recently released one in September that talked about how they stopped "bioweapons." What were said bioweapons efforts? Oh, it was scientists using Claude for grant writing, paperwork and grammar. At national labs.
And this is being used to lobby against "dangerous" open-weight models because gasp a scientist might use them to write a grant! To make better antidepressants.
At what point do they start reporting someone taking apart an iPhone and trying to DIY a repair with a schematic as a thwarted "cyber security incident?"
I might be missing something but... How exactly is this better than telling Claude for example to "install and set up a full RE environment including Ghidra" on my local system and get to work? Like what does this do that my current RE methodology doesn't?
Probably it is not better. I think this is aimed at people who do not have a “current RE methodology”, do not know enough to specify things like Ghidra, etc., but who do have a desire to feel like they reverse-engineered and can reliably predict that a conversation with a chatbot will make them feel that way.
Everybody has their own set of skills and specific scripts and tools to do this stuff. You might use Ghidra as the the kernel of those workflows, but you still want something more than just Claude freestyling, at least for now.
We're using vanilla Claude Code for ArtCraft apps [1], but we are especially careful not to touch Ghidra. We don't want decompilations or reverse engineering to spoil the work we're doing and expose us to copyright infringement.
> Install REA and connect it to this coding agent using npx rea-agents@latest setup. Show me the setup plan for approval, then verify the installation.
We have achieved the next evolution of installation by `curl | bash`!
A big difference between the safety of "next > next > next > finish" and "curl | bash" is one of them is dynamically loaded from an external source that could change between runs, and the other can be fully downloaded and vetted in a single check, and then once it's safe, it's probably safe 10 years from now.
Yeah installation has always been such a security issue. So many programs are just random links that download a file. You have to trust that the host has not been compromised all packages that were used to build it were not compromised etc.
With ai models getting better we may be able to do analysis on the actual underlying bytes of the files we download to properly scan them for malicious code patterns and build systems which sandbox programs and watch inbound and outbound traffic/ system level actions from them and flag suspicious requests for further analysis by smarter models.
REA shows that ai are very good at understanding low level code and reverse engineering it so this could potentially be applied to application level security aswell.
Now there are no excuses to reverse engineer the most notorious closed source binaries out there including from Nintendo's system software to CUDA, and nvcc from Nvidia and make it all "open source".
The only problem is the lawyers at all those companies will be readying their lawsuits, and given they have tons of money; they do not care and will come after anyone.
Adobe product clones like Photoshop and Illustrator: https://www.youtube.com/watch?v=eFB79TYI-Vw
Adobe after effects clone: https://www.youtube.com/watch?v=5mi_tYSdkWQ
MS Office suite clone: https://www.youtube.com/watch?v=U_jTYMOlXio
https://github.com/storytold/photocraft (inspired by Photoshop)
https://github.com/storytold/wordcraft (inspired by Word)
https://github.com/storytold/pdfcraft (one of the more mature apps)
https://github.com/storytold/vectorcraft (another app close to 1:1 parity)
(etc.)
Using REA for something as high profile as what we're doing is likely to result in lawsuits. We're doing everything we can by the books.
We cannot look at Adobe sources. Use of Ghidra is disallowed.
REA is probably great for personal apps and for abandonware, but I think if you publish the results and it's found to have decompiled the original proprietary sources in discovery, you might be in for a bad time.
As an aside, I've heard a lot of hot takes about how this is the end of Adobe, but I'm pretty sure it misses the point. The main reason people pay Adobe is because it's a familiar line of stable, well-supported, interoperable, and actively-developed products. There's already plenty of cheaper or free alternatives (Davinci Resolve for video, Capture One / Darktable for raw, Affinity for photo editing and vector drawing, etc), and if Adobe survived that, I sincerely doubt they're going to lose pro customers to a vibecoded app where half the stuff is probably subtly broken or left as a TODO, and that will be abandoned in a week, because the whole point was to get that 1M YouTube views.
Longbets 1 week, haha.
We're working our asses off on this.
Most of the team are artists who use these tools actively and we want the replacements for ourselves. I'm a filmmaker, so you can imagine my frustration of being bitten by the "unsubscribe fee".
For example, I use Claude as a bouncing wall for my thoughts and I pointed out that,
This was rejected for "Safety," Note, the image here was the Library of Congress' page on DMCA exceptions.Fundamentally, the idea that you can't reverse engineer things, make things, learn about biology or physics without permission is strange to me. These machines have been trained on the sum intellectual output of humanity, the global intellectual commons, and are being used to close off that commons?
I would be OK with their right to create such restrictions if they weren't lobbying the Government to restrict others, thereby ensuring that they control humanity's intellectual commons well into the future.
Perhaps I'm naive, but I think it's better for humans and the machines if we can all think, learn and build. But then again, I'm the kind of person who rejects the doomer pill.
It's worth talking about the fact that you can't even talk about DMCA to a model trained on the Library of Congress unless you're one of the approved people. And that's before reverse engineering something or writing code.
So in this future, it sucks to be you if you're someone trying to make your small app more secure, someone trying to upskill, a tinkerer trying to bypass corporate lockdowns for a device they own (a recognized DMCA exception, btw), a teenager trying to learn about security...
It locks away much of the richness that produced hacker culture behind glass. You can look at their press announcements and PR pieces, but you can't touch.
And as they're lobbying the government for "sensible regulation," this inevitably leads to a future where computing is controlled.
It's the direction their existing reports are taking. They recently released one in September that talked about how they stopped "bioweapons." What were said bioweapons efforts? Oh, it was scientists using Claude for grant writing, paperwork and grammar. At national labs.
These people are basically proud of impeding real research to make better painkillers and study a neglected tropical disease, https://news.ycombinator.com/item?id=49651727
And this is being used to lobby against "dangerous" open-weight models because gasp a scientist might use them to write a grant! To make better antidepressants.
At what point do they start reporting someone taking apart an iPhone and trying to DIY a repair with a schematic as a thwarted "cyber security incident?"
Are you feeling the "Safety?"
(Who knows if this'll be true 6 months from now.)
[1] https://github.com/storytold
Started in the repoprompt (https://repoprompt.com/) community.
Good stuff.
> Install REA and connect it to this coding agent using npx rea-agents@latest setup. Show me the setup plan for approval, then verify the installation.
We have achieved the next evolution of installation by `curl | bash`!
With ai models getting better we may be able to do analysis on the actual underlying bytes of the files we download to properly scan them for malicious code patterns and build systems which sandbox programs and watch inbound and outbound traffic/ system level actions from them and flag suspicious requests for further analysis by smarter models.
REA shows that ai are very good at understanding low level code and reverse engineering it so this could potentially be applied to application level security aswell.
https://www.youtube.com/watch?v=tByxdDiRdPM
The only problem is the lawyers at all those companies will be readying their lawsuits, and given they have tons of money; they do not care and will come after anyone.