Court agrees with EFF: Utah's VPN law demands a technical impossibility (eff.org)

390 points by hn_acker a day ago

SoftTalker 5 hours ago

> platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely

Is it even possible to reliably know that a connection is from a VPN? Anyone can proxy through a random hosting provider.

happyPersonR 3 hours ago

Requires the vpn provider to snitch and possible tag the ip frames or http frames lol

Folks would just host their own vpns various places and this would be pointless ….

unglaublich 3 hours ago

It's all just an effort to control the 90%.

pkilgore 2 hours ago

campbel 43 minutes ago

You can do for free with tailscale exit nodes. Just have a friend in a different location host for you or buy some compute space somewhere

mmooss 2 hours ago

> Folks would just host their own vpns various places and this would be pointless

In the real world, very few people have that capability.

mey 2 hours ago

sparkling 3 hours ago

Detection can be based on the IPs themselves, no packet tricks required. Plenty of services can do that: https://focsec.com/

Now of course, if your VPN is a home-lab style VPN where you are connecting to a little wireguard box sitting in your own home, that is a totally different story.

compiler-guy 2 hours ago

not_a_bot_4sho 4 hours ago

Kinda.

I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)

I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying

Aurornis 4 hours ago

That's not the same. You get blocked because the IP address you're coming from is associated with a VPN list, not because they're analyzing the traffic in detail.

The simplest methods block known datacenter IP ranges like you thought. More will score it based on several heuristics and a reputation over time. If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.

a4isms 3 hours ago

manquer 4 hours ago

Mozilla VPN runs on Mullvad who are transparent and publish active server and IP lists https://mullvad.net/en/servers.so trivial to block them without blocking all of Azure/GCP/AWS[1]

There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.

The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).

Netflix are/were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.

[1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.

kevincox 3 hours ago

alnwlsn 4 hours ago

My home internet is on a CGNAT, so I experience a lot of the same. Ironically, sometimes a VPN will get through.

semiquaver 2 hours ago

Right, all you see is the IP address. And anyone in the world can set up an “individual” VPN just for them on a cheap VPS or cloud server anywhere else in the world. There’s no technical way to accomplish what they’ve mandated, only something approximating it like “block all connections from known commercial VPN services”.

ad_fontes 4 hours ago

Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.

TeMPOraL 4 hours ago

All it would take is for a major ISP in Utah to route everyone through a VPN, and boom, it's the same picture.

irenaeus 4 hours ago

Yeah but the state of Utah could just tell them to knock it off because they're the state.

michaelbuckbee 3 hours ago

Isn't this kind of what Apple's Private Relay is?

greyface- 2 hours ago

TCP MSS < 1500 bytes can be a tell, although it will sometimes falsely identify non-"VPN" tunnels.

eptcyka an hour ago

There are sooo many people out there who are clamped to something far lower than 1500. MTUs below 1280 are not that exotic either.

On the other hand, using Masque for TCP transfers will probably fool a server to believe the MSS is 1500.

mahboi 4 hours ago

It's hard to find a proxy or VPN that isn't flagged as such. People pay extra for residential proxies.

SV_BubbleTime 2 hours ago

I’ve been using different VPNs for years for work. I’m starting to come around to the value of a residential proxy service.

It’s starting to get annoying that things aren’t working. They’re shooting themselves in the foot though.

If they didn’t block VPNs, they would at least know what category to group them in.

babelfish 2 hours ago

It seems like withdrawing from Utah is the obvious option

gwbas1c 2 hours ago

That was what the law attempted to do: Ban porn in Utah.

There is a very vocal anti-porn group in Utah. They do things like put up massive billboards that say "[Store name] sells porn." (Which is basically free advertising instead of shaming.)

LoganDark an hour ago

> Is it even possible to reliably know that a connection is from a VPN?

No, it's not possible. You can only try to identify known protocols or suspicious patterns of data, timing or entropy. Theoretically, with a big enough collaboration, you could hide a VPN behind shaping traffic patterns and request order towards hundreds of different servers, and there's just no method of traffic analysis that can possibly identify that without prior knowledge.

Like, some firewalls try to identify an absence of connections outside the VPN, or an abnormal volume of data over a sustained period of time. But all that goes out the window when, say, you are connecting to hundreds of real servers at all times and only exchanging, say, basic HTTP requests with each one. For all they know you just have a million browser toolbars installed. They wouldn't know if the choice of request, order and timing encodes information because they wouldn't be able to prove what the client's intentions are in sending it or what the servers do with it.

If you tried to identify it, you would block every real connection.

I believe some VPN providers are beginning to play with things like this, but the problem is really that it's impossible to provide this. It only really works when you run it yourself, because that's the only way others don't know. So they're having to settle for compromises, like Mullvad's DAITA, which still uses a single server but tries to avoid showing tells of a VPN connection as opposed to something else like streaming.

codedokode 4 hours ago

You do not need to know "reliably". You can block everything remotely suspicious, and in case someone is blocked by mistake, they can file an application with all necessary documentation proving the connection is not a VPN.

llama052 4 hours ago

Sounds like the great firewall of China. Pretty wild how much we are regressing in the states to say this out loud.

Let’s block traffic on the internet blindly just in case someone is looking at an adult website.

hn_acc1 3 hours ago

ranger_danger 4 hours ago

Not when the definition of VPN is subjective. I could proxy/VPN through a friend's house and nobody would ever know it wasn't them.

EvanAnderson 3 hours ago

A lot of law is adjudicated based on the intent, not the black-and-white definition. Proxying your traffic thru a friend's house (VPS in another location, etc) would be considered a "VPN" by a court. Definitional hacks, for the most part, don't fly with judges.

To handle the matter technically Utah would need a "great firewall of Utah" and a legislative mandate that all ISPs route thru it. Somehow they'd have to factor-in signals from cellular sites neighboring states and satellites.

irenaeus 4 hours ago

This requires a lot of extra work though, and extra work is downward pressure on the behavior (underage people looking at pornography) that the state of Utah is trying to exert downward pressure on.

The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.

Rohansi 4 hours ago

codedokode 4 hours ago

Yes but isn't it suspicious that all your traffic goes to the friend's house and not to Facebook and Reddit? If you claim it is not a VPN does it mean your friend is providing illegal unlicensed hosting? That's even worse.

malfist 4 hours ago

iAMkenough 4 hours ago

ranger_danger 4 hours ago

zen928 3 hours ago

gorgoiler 2 hours ago

The classic: ping the endpoint address, then “ping” the code. If the IP address comes back in 30ms but the JavaScript responds in 330ms, then the client is probably 300ms further away than they say they are claiming.

usernomdeguerre 4 hours ago

>As we’ve said time and time again: the internet will always route around censorship.

Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.

Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.

Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.

tialaramex 4 hours ago

The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.

Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.

The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"

kccqzy 3 hours ago

Yes China will kill your network connections. And that is proof that Internet cannot route around censorship. Any time Internet routes around censorship China finds a new way to censor it.

Normal people don’t care about “downgrade” or “decrypt” or “intercept” they care about availability.

anamexis an hour ago

nazcan 3 hours ago

My guess is if you are in China they can MITM you with their own root certs.

JoshTriplett 3 hours ago

hnav 3 hours ago

tenacious_tuna 3 hours ago

> Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS

I mean... They could, though, no? If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.

tialaramex 2 hours ago

nemomarx 4 hours ago

Is China that successful at it lately? I see a lot of posters and info from China getting around the great firewall, and my understanding was that they don't really care if 1% of users do that so long as it mostly holds and only the technical minded or really fixated will see it.

So there is a route around censorship, but maybe the public doesn't really care about it.

Scaled 4 hours ago

There is also the difficult reality that the government doesn't need to block vpn entirely, but just make it a credible risk of being detected. If you have to worry about the state police barging into your home, you are likely to decide it isn't worth the risk and self-regulate.

jason1cho 4 hours ago

I'm not sure whether it's 1% or 0.1% or only Xi Jinpin can access YouTube. China can adjust the surveillance level dynamically. It's a matter of cost and effect.

hnav 3 hours ago

snohobro 4 hours ago

I’m pretty sure with Iran, and I assume other authoritarian nations, the state controls what traffic can and cannot leave their borders. When they go dark, they just effectively cut off access to the outside world entirely. Sure they may have their own state run servers that provide some services, but then they can inspect and manage all traffic being routed inside the country. Don’t have to try and find the VPN if there’s just no traffic.

I suppose Utah could impose some sort of strategy here, but would be so burdensome and anti-American I’m not sure they could pull it off. Instead of a blacklist of sites dictated by the site provider, you go the other way where all Utah ISPs maintain a whitelist of IPs permitted to Utah citizens. Any traffic attempting to reach a non-white listed IP, would be rejected.

hn_acc1 3 hours ago

We have a data center in Utah.. And I'm sure some of our customers are storing "adult" material.. Are we now banned?

matheusmoreira 2 hours ago

The internet will always route around censorship in principled western nations.

It's a politico-technological arms race. They make their laws. We make technology that completely nullifies their laws. They need to increase their tyranny in order to enjoy the same level of control they had before. The end state is either a totalitarian government or an uncontrollable population.

I used to think that we'd find some kind of equilibrium along the way, that we'd eventually discover the government's limits: some principle they refuse to break, some line they refuse to cross...

But the truth is these tyrants have no limits whatsoever. They'll stop at nothing in their quest to control the flow of information.

TeMPOraL 4 hours ago

It's never been true.

The layer 2 and 3 of ISO/OSI stack does indeed "route around censorship". But the Internet as we know it is all Layer 7, and it's as centralized as it gets.

That's why regulators often aim straight at Layer 7 entities - companies providing consumer services over the web. Because no matter how unblockable the route between you and some server is, it doesn't mean anything when the server itself is refusing to talk to you.

mxkopy 4 hours ago

What about p2p and less scrupulous actors like TPB? I guess in China the former is probably more effective but this sort of thing is immediately what I thought of when I read OP

EvanAnderson 3 hours ago

TJSomething 4 hours ago

It seems like Utah could do mostly do this by intercepting all consumer traffic.

jason1cho 4 hours ago

Just buy the surveillance equipment from Russia and get it done.

iAMkenough 4 hours ago

With some sort of whitelist of IP addresses that consumers, travelers, and business executives are allowed to connect to while in the state?

A VPN/proxy could exist at almost any single address at any given time.

abecedarius 3 hours ago

It's true unless we let freedom of speech and the press be interpreted narrowly, as the right to flap our jaws and to press paper against ink. That is up to us collectively.

simlevesque 3 hours ago

> Over the last two years, Iran officials warned that wider use of the satellite internet service could make communication controls within the country "ineffective", adding the regime has failed to produce an adequate policy response.

> “I sometimes joke that we might as well turn the Ministry of Communications and the Supreme Council of Cyberspace into amusement parks, because they will no longer serve any purpose,” Hakami said.

https://gulfnews.com/world/mena/iran-official-says-starlink-...

mahboi 3 hours ago

There will always be >0 people who find a way around censorship, that's about it. It's not bad AND ineffective, that's a contradiction.

encom 3 hours ago

It's certainly less true than it was. It depends on how Matt Prince feels on any particular day.

To a large degree, most of the internet today is ultimately controlled by a few people. If what you have to say pisses off these people, and someone is determined to keep you off the internet, you have a problem. Kiwi Farms is a well known example, and continues to suffer under regular DDOS attacks. Regardless of how you feel about KF, it's undeniable that a) this nonsense has streissanded the site enormously and b) it's speech you don't like that needs protection.

Also there was the whole covid "misinformation" garbage fire... I certainly do not want my government or some megacorp to decide what can and can't say or read.

And going beyond the internet, I just want to remind you Americans, that your 1st amendment is almost unique (to my knowledge). Enjoy and protect your offensive, hateful, blasphemous, extremist, and deeply unpopular speech.

1vuio0pswjnm7 an hour ago

"As we've said time and time again: the internet will always route around censorship."

It won't route around self-censorship that arises out of surveillance

Nor will it take a stand against SNI which is a dead simple means of implementing censorship that's in widespread use every day for years

newsclues 25 minutes ago

To big to fail social media is a problem for this

JSR_FDED 5 hours ago

The church of LDS is no stranger to technical impossibilities

roughly 5 hours ago

There are a category of things that are technically impossible until a burly man threatens to break your arm if you don't do them, and a category of things that are still impossible.

Doesn't help your arm, but when they're asking for things in that second category, it doesn't help them either.

cwillu 5 hours ago

But until you've broken their arm, you can't know which category you're in.

not_a_bot_4sho 4 hours ago

m463 3 hours ago

I remember talking about voting fraud with an indian friend. He said it was more overt in india - a burly guy would grab your finger and make it press the "correct" voting machine button.

thayne 3 hours ago

pseudosavant 2 hours ago

No stranger to expecting to apply their morality to all people, even those who have a very different set of beliefs. Just a niche brand of christian nationalism seeking to subjugate everyone to their ways.

cheesecakegood 2 hours ago

Most Mormons are not Christian nationalists and in fact tend to oppose such, especially in comparison to most red states and evangelicals.

howunfortunate 2 hours ago

Huh? Is this comment referring to something specific or is it just a general swipe at a religion that's unliked around here?

nadermx an hour ago

Remember to renew your support for the EFF. They take on some interesting cases

forshaper 2 hours ago

Can someone explain why it wouldn't work to have porn companies use only certain domains, and filter based on those domains, if people are so intent on blocking it?

andrewflnr an hour ago

The smart version of this is that adult content providers send a header or something with every response that contains NSFW, and then you use parental controls on client devices to not show those responses. This even works for sites that show a mix of kid-friendly and adult content cough reddit cough. It offers fewer opportunities for general purpose censorship, though, so there's less interest.

petcat 31 minutes ago

The US Congress evaluated [1] the legality of forcing adult websites onto certain TLDs in the 2000s and it was determined to be legally ambiguous and would almost certainly face substantial 1st amendment challenges. So they didn't pursue it.

https://www.everycrsreport.com/files/20080714_RL33224_1e6b93...

braiamp 2 hours ago

Because you shouldn't get behind a thing that shouldn't exists. Technical solutions to societal problems are and will always be naught and fraught with unnecessary jump roping. In this case, the content itself isn't dangerous, what is dangerous is consuming it without the correct context, ie. education.

bell-cot 2 hours ago

What's the enforcement mechanism if some porn company in Elbonia "forgets" and uses hothothot.el, instead of hothothot.porn?

kstrauser a minute ago

Here my genius self sits, momentarily wondering what M-x hothothot does in Emacs.

rhcom2 4 hours ago

> It even went so far as to prohibit websites from offering instructions on how to use a VPN to bypass these checks

How is that not a blatant first amendment violation?

MBCook 2 hours ago

Because we don’t like people doing it. Duh.

criddell 3 hours ago

It is, but the first amendment isn't absolute.

CamperBob2 2 hours ago

It is, but our judges and legislators find it expedient to pretend it's not.

tzs an hour ago

rhcom2 2 hours ago

I guess this could be speech integral to criminal conduct but seems like a stretch.

kramer2718 3 hours ago

Fascism is on the march. Dirty pictures aren't the real reason governments want this level of control over the internet. You can be sure that we'll see worse. Glad we won this battle.

mahboi 4 hours ago

How is this impossible? DraftKings does it for California visitors.

compiler-guy 3 hours ago

DraftKings does it in a way that is good enough to comply with California law, which doesn't require perfection.

This Utah law requires perfection.

mahboi 3 hours ago

Oh I see, "An individual is considered to be accessing the website from this state if the individual is actually located in the state regardless of whether the individual is using..." as mentioned in the injunction https://www.courthousenews.com/wp-content/uploads/2026/09/ay... So yeah the law would basically require everywhere to perform age verification, where the law says it only has to be "commercially reasonable."

Ukv 3 hours ago

I'm not in California and DraftKings blocks me connecting with a VPN, so they just don't seem to be distinguishing whether a VPN user is in California (which is the impossible part of this law).

mahboi 3 hours ago

Right, they just block all VPN users, which would comply with the law

Ukv an hour ago

iAMkenough 3 hours ago

abirch 3 hours ago

they want to stop VPN traffic. If it's a plain IP address it's easy. VPN makes it hard.

mahboi 3 hours ago

I understand. You can't use DraftKings via a VPN.

abirch 3 hours ago

stefangordon 3 hours ago

If you want to ban ISP's in your state, or build a state firewall, or arrest your citizens, you are welcome to do so - but what happens on servers outside your state that your state is choosing to connect to is clearly none of your business.

Seems like we need a fundamental challenge to the concept that you have any jurisdiction whatsoever.

ryandrake 3 hours ago

Being able to tie an IP to a rough physical location was, in retrospect, a huge Internet design mistake. IPs should be like random UUIDs. They should have been designed to get assigned randomly when you obtain one, rotated / thrown away periodically, with no hierarchical numeric relationship with the ISP that is assigning them.

wildzzz 2 hours ago

It was much easier to assign blocks of IPs to an ISP rather than a 4.3B line lookup table. And how would you ensure that an address has been rotated? How do you determine who the real owner of an IP is when collisions occur? You're asking for a worldwide atomic database propagated to all routers in the days where a 32bit number was considered massive.

nikanj 4 hours ago

Since when do lawmakers cared about technical impossibilities?

calvinmorrison 4 hours ago

In 1897 Indiana almost passed a law defining Pi as 3.2. These jurists have never cared about reality.

ceroxylon 3 hours ago

Wow, that is a wild read, thank you: https://en.wikipedia.org/wiki/Indiana_pi_bill

mahboi 2 hours ago

They seem to know what they're doing here. A website can comply as long as they perfectly geofence (impossible) or do "reasonable" age verification. "Reasonable" only for the latter. So they basically want these sites in any US state to do age verification.

stonogo 2 hours ago

I'm not sure your claim is backed up by the evidence you've provided (to wit, that Indiana did not pass the bill).

irenaeus 4 hours ago

Not sure what the impossibility is. VPN's have a set of exit relays. If traffic is coming from one of those exit relays, it's coming from a VPN, so adult websites can be required to block traffic from those exit relays. What am I missing?

cryptonector 2 hours ago

https://le.utah.gov/~2026/bills/static/SB0073.html

| An individual is considered to be accessing the website from this state if the individual is actually located in the state, regardless of whether the individual is using a virtual private network, proxy server, or other means to disguise or misrepresent the individual's geographic location to make it appear that the individual is accessing a website from a location outside this state.

But how can any site check if a client is a) a VPN client (typically this can be known because VPN exit node IPs can be learned), __and__ b) in Utah?

The impossibility lies in (b). Effectively this forces any affected companies having a nexus to the state of Utah to forbid VPN clients. I think that's a bit too far-reaching. It would be much more practicable instead to ask VPNs to disallow Utah client exits to affected sites w/o age checks -- VPN services aren't free, so VPNs basically can do age checks.

Given that this could have been written to be feasibly implemented, either this text was written to cause a controversy, or this text was written by people who don't know how things work. Either way, this text cannot be enforceable as written. The Utah legislature can easily modify this to be enforceable (see above), so it's not like a court striking this down might be playing partisan games just by striking it down.

Dfiesl 4 hours ago

The law is only meant to apply to citizens of Utah though. Blocking all exit relays would mean that absolutely anyone accessing that website would not be able to do so from a VPN which burdens people outside of Utah too.

irenaeus 36 minutes ago

This is what I was missing. Demanding that porn sites block VPN traffic (or only accept residential traffic) would mean that everyone everywhere using a VPN gets blocked not just in Utah.

I still suspect there's some kind of solution. Like Utah could tell VPN providers that if they service a customer in Utah then the VPN provider can't route traffic to adult sites. Or put the burden on the VPN provider to do age verification if porn is gonna be available through the VPN.

Come to think of it, I'm still a bit confused as to why VPNs are even relevant because it would seem to me that age verification would be done through some kind of having-credit-card type scheme which VPNs are entirely irrelevant to. I even read the article and I'm still confused. Oh well.

Aurornis 4 hours ago

The law requires blocking all VPN access.

It's impossible to have perfect knowledge of the entire set of VPN exit node addresses.

nikanj 4 hours ago

Sounds like a problem for those pesky, nasty porn websites, not a problem for the good christian lawmakers..

logicchains 4 hours ago

gchamonlive 4 hours ago

  The law likely violates the U.S. Constitution’s prohibition on passing laws that significantly burden businesses and people outside Utah’s borders.
  SB 73 burdens the rights of all internet users outside of Utah because it requires adult websites to either know every visiting user’s physical location, and then block those in Utah, or to verify every visitor’s age just in case they might be in Utah.
It's technically impossible to both implement Utah's law and respect the constitution. To make it technically feasible you'd need to either change the constitution or federalize the law.

llama052 4 hours ago

I would think that requiring adult websites to essentially block all VPN traffic to be pretty heavy handed and hardly a solution. Especially considering there are many reasons to use a VPN.

gambiting 4 hours ago

It's impossible to have a full and complete list of VPN exit nodes, for the simple reason that no company publishes the full list, and also technically if you set up an OpenVPN server on digital ocean and connect to that you're also using a VPN but no one would know your address is hosting a VPN server.

irenaeus 4 hours ago

So it would be possible if the state demanded that VPN companies provide adult sites with continuously updated lists of their exit nodes.

It also seems to me like Utah could just demand that adult sites only accept traffic from residential ips.

techjamie 4 hours ago

moate 4 hours ago

gambiting 4 hours ago

knicholes 3 hours ago

I think "The Church" (The Church of Jesus Christ of Latter-Day Saints) is trying to keep Pornhub from publishing stats of how many ~people~ ~righteous Church members~ Melchizedek Priesthood holders are whacking to "cosplay porn" and "lesbian porn".

Henchman21 2 hours ago

Let’s not forget that “dirty mormon girls” is a category on pornhub

bnteke 2 hours ago

brb