CSIPE

Published

- 20 min read

Utah Tried to Make Websites See Through VPNs. The Court Found the Limit


Books by the author

Compare all 5

As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.

A website receives a connection from a server in Colorado. The person behind it may be sitting in Salt Lake City, Boston, or a hotel in Berlin. A virtual private network has done exactly what its user asked: it has replaced the user’s visible network address with the address of an intermediary.

Utah told certain adult websites to look past that intermediary and identify visitors who were physically inside the state. The law did not give the sites a method that worked every time. It still attached liability to the answer. On 24 September 2026, a federal judge blocked that demand while the case continues, finding that the “actual-location” provision likely placed an excessive burden on interstate commerce (U.S. District Court for the District of Utah: Memorandum Decision and Order).

The ruling deserves a precise reading. Utah’s wider age-verification law remains. The court enjoined one provision, Utah Code section 78B-3-1002(3), that treated a person actually located in Utah as a Utah user even when a VPN or proxy disguised the connection. The order also said that nothing in it stopped the state from enforcing the law’s other sections (Free Speech Coalition: District Court Blocks VPN Provision of Utah AV Law).

That narrow result still carries a useful lesson. A VPN can hide one location signal, but it does not make a person invisible. A website can collect other clues, but clues do not become certainty because a statute wants certainty. Privacy policy fails when lawmakers pretend either side of that sentence is false.

What the court actually stopped

Utah already required covered adult-content sites to verify the age of Utah users. Some sites responded by blocking addresses that appeared to come from the state. A person using a VPN could choose an exit server elsewhere, so the destination site would see the exit server’s address instead of the person’s ordinary address.

Senate Bill 73 tried to close that route in 2026. Its actual-location provision extended the law to a person physically present in Utah even when technology obscured that fact. The dispute then became brutally practical: how could a website know, with enough confidence to avoid liability, where every masked visitor was sitting?

Aylo, the parent company of Pornhub and other adult sites, challenged the provision. Judge David Barlow’s 24 September order granted a preliminary injunction. That stage of a case does not finally strike a law from the books. It asks whether the challenger is likely to succeed, whether harm will occur without temporary relief, and how the competing interests weigh while the lawsuit proceeds.

The official order identifies the ground plainly. The plaintiffs showed that the actual-location provision was likely to violate the Constitution’s dormant Commerce Clause, that irreparable harm would follow, and that the balance favoured an injunction (U.S. District Court for the District of Utah: Memorandum Decision and Order). In ordinary language, one state appeared to be imposing a heavy operational burden on internet activity far beyond its borders.

The burden came from the mismatch between the legal duty and the available measurement. Utah’s Attorney General argued that companies could make a reasonable effort. The court returned to the enacted text. According to local reporting, Judge Barlow wrote that a court must analyse “the statutory text the Legislature passed into law, not just the Attorney General’s proposed enforcement of it” (KUER: Federal judge blocks Utah’s VPN update to its online porn age verification law).

That distinction matters. An official promise to act reasonably can change. Statutory language travels to every compliance officer, lawyer, insurer, and vendor that must decide how much risk to accept. If the text creates liability for one missed Utah visitor, a site has to design for the missed visitor, not for the press conference.

The judge described the result as a demand for perfect geolocation when perfect geolocation is unavailable. The order used Aylo’s reported 28 million daily users to show the scale. If any one of those visitors might be in Utah behind a masked connection, the cautious response would be to verify them all or block a much wider class of traffic. A state rule would then shape access for people in places that had never enacted it.

The injunction stops enforcement of that actual-location provision until the court orders otherwise. Other parts remain outside the order. The Free Speech Coalition, which has an obvious industry interest in the case, published the operative language and told covered sites to keep complying with the rest of Utah’s age-verification law (Free Speech Coalition: District Court Blocks VPN Provision of Utah AV Law). That is a better description than saying Utah’s whole age gate disappeared.

One more limit deserves attention. The Electronic Frontier Foundation noted on 1 October that Aylo’s lawsuit did not challenge the provision restricting covered sites from sharing information about using VPNs to bypass the checks (EFF: Court Agrees with EFF, Utah’s VPN Law Demands a Technical Impossibility). The location mandate and the speech restriction may sit in the same political argument, but the September order dealt with the former.

Precision protects the lesson. A broad victory slogan would be easy to share and wrong to rely on. The live result is smaller: Utah cannot currently enforce one demand for perfect knowledge of a masked visitor’s physical location against these plaintiffs. The underlying case continues.

A VPN changes the address the website sees

Open a normal connection from home and the destination usually sees an internet address assigned somewhere along your access route. That address may place you near a city, in the correct region, or only in the correct country. Mobile carriers, corporate gateways, shared networks, and stale location databases already make the result imperfect.

A VPN adds an intentional intermediary. Your device creates an encrypted tunnel to a VPN server. The destination receives traffic from that server, so its first network-level location clue points to the server. If you are in Utah and choose an exit in Colorado, the website sees Colorado’s address.

That is useful protection with a clear edge. The coffee-shop network can see that you connected to a VPN, but it cannot read ordinary traffic inside the tunnel. Your internet provider sees the same tunnel and its endpoints rather than each destination in the old form. The destination loses your household address and sees the VPN address. The VPN provider gains a privileged place in the route.

Nothing in that design erases every clue. A logged-in account may contain a billing country, an old address, or years of access history. A browser exposes a time zone, language, screen details, and other characteristics. A payment can carry its own regional information. A phone app may have location permission. Cookies can join today’s VPN visit to yesterday’s ordinary connection.

Those signals can support an estimate. They can also conflict for innocent reasons. A traveller keeps the home time zone. An immigrant uses a different language. A company routes staff through a central gateway. A person pays with a card issued abroad. A privacy-conscious user blocks cookies and never creates an account. Shared clues narrow possibilities without producing a reliable physical coordinate.

Utah’s proposed administrative approach reportedly discussed signals such as connection latency, device time zones, and language settings. EFF argued that these indicators are unreliable and can misclassify ordinary users (EFF: Court Agrees with EFF, Utah’s VPN Law Demands a Technical Impossibility). The criticism lands because each signal answers a different question.

Latency measures how long data takes to travel along a route. Congestion, wireless conditions, server load, and routing choices change it. A short delay might suggest proximity to an exit server, but it cannot prove where the person holding the device is sitting. Device time zone describes a setting. Language describes a preference. Both may be evidence in a fraud model. Neither is a border checkpoint.

A site could combine the clues into a score. Suppose an exit address belongs to a known VPN, the browser reports Mountain Time, previous visits came from Utah, and the account uses a Utah billing address. The site might decide that this person is probably in Utah. Change the account history and billing record, and the confidence falls. A score always has a threshold, and every threshold produces false positives and false negatives.

The legal problem appears when the law treats a probabilistic score as a fact. Set the threshold low and people outside Utah get blocked or forced through an age check. Set it high and some people inside Utah pass without one. Demand no mistakes and the operator’s safest choice becomes universal verification or a broad refusal to serve masked connections.

That is the mechanism behind the interstate burden. It is not a mystical property of VPN encryption. The website lacks a trusted location sensor under its control. The state placed the consequence of uncertainty on the website, while the website served a network whose users and intermediaries crossed every state line.

Security engineers deal with uncertain signals every day. A bank can flag a strange login and ask for another factor. A mail provider can slow a suspicious sender. A company can combine device history and network data before allowing a sensitive action. These systems manage risk. They do not discover a perfect fact from imperfect inputs.

Law can require reasonable controls and define how mistakes are handled. It can specify a safe harbour for documented efforts. It can limit collection, retention, and secondary use. The blocked provision instead asked the court to accept a location duty whose failure case reached everyone. The judge refused, at least for now.

More location checks would create another privacy system

There is a tempting answer to uncertain location: collect more. Ask for device coordinates. Compare account history. Read browser settings. Examine connection timing. Buy a commercial risk score. Require an identity document and connect it to a location record.

Each extra input creates a new data path. The site may send device details to a geolocation vendor, an age-assurance service, a fraud company, or all three. Those firms need logs to operate, diagnose disputes, and bill customers. A rule aimed at one class of content can leave behind an infrastructure that observes many ordinary visitors.

The information has value beyond the original check. An exact location, identity assertion, browsing category, and timestamp can reveal sensitive behaviour. Even a record that says “adult, allowed, Utah probability low” may become useful when joined to another database. The risk grows with retention and with the number of organisations that receive the event.

This does not mean every age-assurance design requires a passport database at every website. A system can prove a limited fact, such as whether a person is over a threshold, without handing the destination a full identity. Credentials can be designed for selective disclosure. Vendors can minimise logs. Browsers and operating systems can carry age signals. None of those choices solves the separate demand to know where a VPN user is physically sitting with perfect accuracy.

Biometric Update’s 28 September account captured the distinction between practical detection and legal certainty. It reported that Utah suggested cross-checking time zone, language, currency, and account history, while the judge found that the statute effectively imposed strict liability because “reasonable” did not appear in the actual-location duty (Biometric Update: Utah’s VPN age check provision blocked over strict geolocation standard). A collection programme can improve a guess without changing the wording that punishes the remaining error.

False positives have a human cost. A traveller outside Utah may be denied access because their account was created there. A journalist using a newsroom VPN may be forced into an identity flow because the exit address sits in the wrong place. A person escaping domestic abuse may avoid an age check that requests documents or face data because the privacy cost feels unsafe. A blunt block can make lawful speech unavailable without explaining which clue caused it.

False negatives carry the policy cost. A teenager may use an exit server, a fresh browser profile, ordinary language settings, and no account history. A site that depends on auxiliary clues sees little. The people most willing to evade the rule will test its edges, while ordinary users present stable signals and absorb the extra collection.

That asymmetry is common in surveillance systems. Cooperative people provide the cleanest data. Determined people change their behaviour. The system becomes very good at sorting the compliant and remains uncertain about the target that justified it.

The answer cannot be “collect until uncertainty disappears.” Uncertainty does not disappear. It moves into vendor models, exception queues, appeals, and quiet denial decisions. Meanwhile, the collected material becomes a security liability of its own.

A defensible rule starts from the minimum fact needed for the policy goal. It limits who may ask, what proof may contain, how long records survive, who can receive them, and how a person challenges a mistake. It also admits the residual error. Hiding that error behind the word “technology” gives lawmakers a promise that engineers cannot keep and users cannot audit.

The ruling does not make VPNs magic

Privacy advocates can make the opposite mistake. A court called perfect geolocation impossible, so a slogan emerges: websites cannot know anything about a VPN user. That claim would sell VPN subscriptions. It would also set people up to fail.

A VPN replaces the visible network address and protects traffic between your device and the VPN server. It does not clear account history, browser storage, payment records, device identifiers, or the words you type into a form. If you log into the same account before and after turning it on, the service still knows that both sessions belong to you.

The provider matters too. Your traffic enters the provider’s infrastructure before it reaches the wider internet. The company may have good technical and organisational controls. It may make narrow promises, publish audits, or design systems that reduce logging. You still moved trust from the local network and access provider toward the VPN service.

A VPN also does little against an endpoint that is already compromised. Malware on the device can read content before encryption or after decryption. A hostile browser extension can observe pages. An app with location permission can ask the operating system for coordinates. The tunnel protects the route, not every process at either end.

The court’s conclusion fits that honest model. Websites cannot geolocate every masked visitor “with perfection,” as the reporting quotes the judge (KUER: Federal judge blocks Utah’s VPN update to its online porn age verification law). The phrase leaves room for estimates, correlations, and mistakes. It rejects certainty, not observation.

Your threat model decides whether that protection is enough. If you want to stop a café operator from tying destinations to your device, a reputable VPN can help. If you want a news site to avoid seeing your household address, it can help. If you log into a named account, pay with your usual card, and grant precise location permission, the changed address will not separate the activity from you.

A person facing a stalker, an employer, a civil lawsuit, or a state investigation needs a different calculation. Which party can compel the VPN provider? Which identifiers reach the destination? Which account joins the sessions? Which device leaks location outside the tunnel? What happens when the connection drops? The name of the tool comes after those questions.

The Anonymity Playbook returns to this edge because it is where privacy marketing does the most damage: a tool can make one route expensive to watch while leaving another route open. The Utah case gives that idea a clean public example. A VPN defeated a simple location assumption. It did not abolish location evidence.

Treat the ruling as protection against an impossible legal standard, not as a certificate of invisibility. That position is less exciting. It is also safer.

The cross-border problem is the durable part

The internet does not stop at a state boundary, but state law still has legitimate work to do. Consumer protection, child safety, privacy, fraud, and speech all involve harms that happen somewhere. The hard question is how a state writes a duty for a service whose users, servers, vendors, and network exits sit in many places at once.

Utah’s actual-location provision put that tension into one sentence. A covered site had to account for a person physically inside Utah even when the connection appeared elsewhere. To avoid missing that person, the site would have to examine visitors outside Utah too. The local rule changed the default for the wider service.

Large platforms often choose one national control rather than maintain fifty technical variants. Smaller services may block a state, block a class of network addresses, buy a vendor’s score, or leave the market. Each response affects people who had no role in the local debate. That is why the court’s commerce analysis matters beyond adult sites.

The next version of this conflict may involve social media, app stores, gambling, health services, or artificial intelligence. Any rule that depends on knowing a user’s state must answer the same operational questions. Which signal counts? How accurate must it be? Who bears a mistake? What happens to a traveller? What evidence proves compliance? How far outside the state may a service collect data to make the decision?

Those questions can produce better law. A statute can define reasonable methods instead of silent perfection. It can protect a service that follows published standards in good faith. It can require independent measurement of error rates. It can forbid reuse of age and location data for advertising. It can demand a deletion schedule and a real appeal path.

The September ruling does not design that system. Courts decide the dispute before them, and this order is preliminary. Utah may appeal, amend the law, or continue the case. EFF reported on 1 October that legislators had indicated they might revisit the issue in a later session (EFF: Court Agrees with EFF, Utah’s VPN Law Demands a Technical Impossibility).

A revision that inserts “commercially reasonable” would still need scrutiny. Reasonable according to whom? A vendor can call a product accurate while measuring only visitors who volunteered ground truth. A regulator can list signals without publishing false-positive rates. A site can follow the checklist and collect far more than the reader expects.

Good rules make the trade visible. They state the policy goal, define the permitted proof, cap the data collected, and assign the cost of error. They also allow a regulator to change course when measurement shows that the system blocks the wrong people or fails to reach the intended cases.

That is slower than ordering websites to know. Slow is useful here. A border drawn in law does not become a sensor in a browser.

What to do without overreading the decision

The practical response depends on your role. A Utah resident using a VPN has different work from a site operator, a privacy engineer, or a legislator. The shared rule is simple: preserve the distinction between a hidden network address and a hidden person.

For an individual, the first job is to decide what you are protecting and from whom. “I use a VPN” is a tool statement. “I do not want the hotel network to see my destinations” is a threat model. The second sentence tells you whether the tool fits.

For a service, the first job is to read the operative order and current law rather than a victory headline. The injunction names one subsection and preserves enforcement of the others. Compliance decisions should come from counsel and the official text, with the data flow mapped before another vendor is added.

For anyone designing policy, the first job is to write down the false-positive and false-negative cases before choosing a technical mandate. If the rule cannot tolerate either kind of error, the required sensor may not exist. Moving the error into private contracts does not repair the design.

A useful sequence looks like this:

  1. Name the protected fact. Decide whether the system needs age, state, legal jurisdiction, account ownership, or consent. Do not collect identity merely because it is easier to buy than a limited proof.

  2. Map every observer. Record what the destination, VPN provider, age-assurance vendor, payment processor, browser, operating system, and network can each see. The gaps between them explain both the privacy protection and the failure modes.

  3. Set an error budget. State what happens when the system guesses wrong. Include travellers, shared devices, corporate gateways, accessibility needs, language differences, and people with no conventional identity document.

  4. Minimise the evidence. Prefer a proof of the needed property over a copy of a document. Limit logs, retention, internal access, and onward sharing. Give the user a route to challenge a bad decision.

  5. Test the bypass and the burden. Measure whether a determined person can evade the control and whether ordinary people are blocked. Publish both results. A system that reports only successful checks hides its most important numbers.

  6. Recheck the legal scope. Preliminary orders change, agencies issue rules, and legislatures amend statutes. Record the date and source for every compliance assumption. As of 3 October 2026, the Utah actual-location provision is enjoined while the wider framework remains.

Individuals can run a smaller version of the same exercise. Check whether the VPN app has a kill switch and whether it covers the whole device or only one browser. Test which address and DNS resolver appear after connection. Review location permission separately. Use different browser profiles or devices when two activities should not join through cookies and logins.

Do not turn that exercise into a hunt for perfect anonymity. Perfect anonymity is the same kind of impossible promise that caused trouble in the Utah law. The useful goal is to remove unnecessary signals, separate activities that should not meet, and know which provider receives the trust you moved.

If an age or location check asks for sensitive material, pause before submitting it. Confirm who operates the check, what fact will reach the site, what data the verifier retains, and how to appeal a mistake. A lawful request can still have a poor privacy design. Compliance does not answer the security question for you.

Site operators should document the decision path outside the scoring vendor. Keep the policy version, signals requested, threshold, user notice, retention period, and appeal result. A dashboard that emits “Utah likely” is not an explanation. When a person challenges a block, somebody needs to reconstruct why it happened without exposing every other visitor’s data.

That record also protects against quiet expansion. A location model bought for age checks can later tempt fraud, advertising, analytics, and law-enforcement teams. Purpose limits mean little unless access and exports are measured. The cleanest sensitive database is the one you never built.

A narrow injunction with a wide warning

Utah wanted a website to recognise a person behind a masked route. The website could gather clues. It could buy scores. It could block broadly. It could not know every visitor’s physical location with the certainty the court found in the statute.

The judge’s answer on 24 September was narrow. Enforcement of the actual-location provision is paused. Other parts of Utah’s law remain, and the lawsuit continues. That scope should survive every retelling.

The warning travels farther. Technical systems produce measurements with limits. A legislature can choose how much error society accepts and who bears the cost. It cannot remove the error by leaving the word “reasonable” out of the law.

Privacy tools have limits too. A VPN changes the network address a destination sees and shifts trust to an intermediary. Accounts, devices, payments, permissions, and habits can still point back to the person. Anyone promising more is selling certainty that the network does not contain.

Keep both truths. Reject laws that demand impossible surveillance, and reject products that promise impossible disappearance. The space between them is where useful privacy work happens: fewer signals, narrower proof, clear failure modes, and rules that admit what the machinery cannot know.

If you want more plain-English analysis without a daily panic feed, join the newsletter. It is one email per month.

Sources