I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)
I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying
Mozilla VPN runs on Mullvad who are transparent and publish active server and IP lists https://mullvad.net/en/servers.so trivial to block them without blocking all of Azure/GCP/AWS[1]
There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.
The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).
Netflix are/were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.
[1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.
That's not the same. You get blocked because the IP address you're coming from is associated with a VPN list, not because they're analyzing the traffic in detail.
The simplest methods block known datacenter IP ranges like you thought. More will score it based on several heuristics and a reputation over time. If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.
Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.
A lot of law is adjudicated based on the intent, not the black-and-white definition. Proxying your traffic thru a friend's house (VPS in another location, etc) would be considered a "VPN" by a court. Definitional hacks, for the most part, don't fly with judges.
To handle the matter technically Utah would need a "great firewall of Utah" and a legislative mandate that all ISPs route thru it. Somehow they'd have to factor-in signals from cellular sites neighboring states and satellites.
This requires a lot of extra work though, and extra work is downward pressure on the behavior (underage people looking at pornography) that the state of Utah is trying to exert downward pressure on.
The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.
> The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.
So if you are legally required to block all VPN users and then fail to actually block all VPN users what is stopping you from being punished for not complying with the law?
Yes but isn't it suspicious that all your traffic goes to the friend's house and not to Facebook and Reddit? If you claim it is not a VPN does it mean your friend is providing illegal unlicensed hosting? That's even worse.
Split tunnel is a thing, and in that instance the platform required to comply (like a porn site) doesn’t have any way to see all your traffic to determine if it’s a VPN/proxy connection or not.
You do not need to know "reliably". You can block everything remotely suspicious, and in case someone is blocked by mistake, they can file an application with all necessary documentation proving the connection is not a VPN.
There are a category of things that are technically impossible until a burly man threatens to break your arm if you don't do them, and a category of things that are still impossible.
Doesn't help your arm, but when they're asking for things in that second category, it doesn't help them either.
>As we’ve said time and time again: the internet will always route around censorship.
Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.
Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.
Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.
The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.
Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.
The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"
It's true unless we let freedom of speech and the press be interpreted narrowly, as the right to flap our jaws and to press paper against ink. That is up to us collectively.
Is China that successful at it lately? I see a lot of posters and info from China getting around the great firewall, and my understanding was that they don't really care if 1% of users do that so long as it mostly holds and only the technical minded or really fixated will see it.
So there is a route around censorship, but maybe the public doesn't really care about it.
There is also the difficult reality that the government doesn't need to block vpn entirely, but just make it a credible risk of being detected. If you have to worry about the state police barging into your home, you are likely to decide it isn't worth the risk and self-regulate.
I'm not sure whether it's 1% or 0.1% or only Xi Jinpin can access YouTube. China can adjust the surveillance level dynamically. It's a matter of cost and effect.
The layer 2 and 3 of ISO/OSI stack does indeed "route around censorship". But the Internet as we know it is all Layer 7, and it's as centralized as it gets.
That's why regulators often aim straight at Layer 7 entities - companies providing consumer services over the web. Because no matter how unblockable the route between you and some server is, it doesn't mean anything when the server itself is refusing to talk to you.
What about p2p and less scrupulous actors like TPB? I guess in China the former is probably more effective but this sort of thing is immediately what I thought of when I read OP
I’m pretty sure with Iran, and I assume other authoritarian nations, the state controls what traffic can and cannot leave their borders. When they go dark, they just effectively cut off access to the outside world entirely. Sure they may have their own state run servers that provide some services, but then they can inspect and manage all traffic being routed inside the country. Don’t have to try and find the VPN if there’s just no traffic.
I suppose Utah could impose some sort of strategy here, but would be so burdensome and anti-American I’m not sure they could pull it off. Instead of a blacklist of sites dictated by the site provider, you go the other way where all Utah ISPs maintain a whitelist of IPs permitted to Utah citizens. Any traffic attempting to reach a non-white listed IP, would be rejected.
> Over the last two years, Iran officials warned that wider use of the satellite internet service could make communication controls within the country "ineffective", adding the regime has failed to produce an adequate policy response.
> “I sometimes joke that we might as well turn the Ministry of Communications and the Supreme Council of Cyberspace into amusement parks, because they will no longer serve any purpose,” Hakami said.
It's certainly less true than it was. It depends on how Matt Prince feels on any particular day.
To a large degree, most of the internet today is ultimately controlled by a few people. If what you have to say pisses off these people, and someone is determined to keep you off the internet, you have a problem. Kiwi Farms is a well known example, and continues to suffer under regular DDOS attacks. Regardless of how you feel about KF, it's undeniable that a) this nonsense has streissanded the site enormously and b) it's speech you don't like that needs protection.
Also there was the whole covid "misinformation" garbage fire... I certainly do not want my government or some megacorp to decide what can and can't say or read.
And going beyond the internet, I just want to remind you Americans, that your 1st amendment is almost unique (to my knowledge). Enjoy and protect your offensive, hateful, blasphemous, extremist, and deeply unpopular speech.
Why does it require perfection? The Utah law has a section on "Reasonable age verification methods" if I'm reading the right thing (EFF doesn't link to the law): https://le.utah.gov/Session/2026/bills/enrolled/SB0073.pdf , and it doesn't say a lot about geofencing other than the site shouldn't tell users how to circumvent it.
I know firsthand that DraftKings' geofencing checks go pretty far. They outright block every commercial VPN, and there are sketchy proxies that kinda get around it but then they want you to install some crap on a phone that reports location. Unfortunately know this from a gambler friend showing me.
I'm not in California and DraftKings blocks me connecting with a VPN, so they just don't seem to be distinguishing whether a VPN user is in California (which is the impossible part of this law).
What stops me from using DraftKings.com from a VPN? I'm at the page right now, but I don't have an account. Will they verify that my IP and home address match or something?
Not sure what the impossibility is. VPN's have a set of exit relays. If traffic is coming from one of those exit relays, it's coming from a VPN, so adult websites can be required to block traffic from those exit relays. What am I missing?
The law is only meant to apply to citizens of Utah though. Blocking all exit relays would mean that absolutely anyone accessing that website would not be able to do so from a VPN which burdens people outside of Utah too.
The law likely violates the U.S. Constitution’s prohibition on passing laws that significantly burden businesses and people outside Utah’s borders.
SB 73 burdens the rights of all internet users outside of Utah because it requires adult websites to either know every visiting user’s physical location, and then block those in Utah, or to verify every visitor’s age just in case they might be in Utah.
It's technically impossible to both implement Utah's law and respect the constitution. To make it technically feasible you'd need to either change the constitution or federalize the law.
I would think that requiring adult websites to essentially block all VPN traffic to be pretty heavy handed and hardly a solution. Especially considering there are many reasons to use a VPN.
It's impossible to have a full and complete list of VPN exit nodes, for the simple reason that no company publishes the full list, and also technically if you set up an OpenVPN server on digital ocean and connect to that you're also using a VPN but no one would know your address is hosting a VPN server.
You'd have to ask every non-residential host online to do the same. As above, you can get a DigitalOcean droplet and ssh -D to it, now you have a SOCKS proxy that for state's concern is doing the same as a VPN.
Utah could demand the moon, it doesn't mean that the federal government would agree they have a right to that demand.
Utah can't tell businesses that service the country (or the world) how to do anything in this regard. You can't demand a list of the VPN exit nodes, because no VPN would ever give you that, and if they're outside of your jurisdiction, how could you possibly enforce it (assuming you got the Feds to agree with your law regulating interstate/international commerce now). You can't tell websites to only accept residential traffic, for the same reasons.
The internet sorta fucks states rights (in a good way).
Why would a VPN company care about what Utah requires if they have no legal presence there(or in the US for that matter)?
Besides, there's no such thing as "residential" IPs. If I set a VPN gate at my mum's house, how would the porn company know?
The "impossibility" is in them saying "we cannot guarantee with 100% certainty that the user isn't using a VPN" and that's correct, they can't - but the law has no provision for that, they are risking fines over something they cannot control.
> platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely
Is it even possible to reliably know that a connection is from a VPN? Anyone can proxy through a random hosting provider.
Kinda.
I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)
I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying
Mozilla VPN runs on Mullvad who are transparent and publish active server and IP lists https://mullvad.net/en/servers.so trivial to block them without blocking all of Azure/GCP/AWS[1]
There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.
The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).
Netflix are/were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.
[1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.
That's not the same. You get blocked because the IP address you're coming from is associated with a VPN list, not because they're analyzing the traffic in detail.
The simplest methods block known datacenter IP ranges like you thought. More will score it based on several heuristics and a reputation over time. If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.
My home internet is on a CGNAT, so I experience a lot of the same. Ironically, sometimes a VPN will get through.
It's hard to find a proxy or VPN that isn't flagged as such. People pay extra for residential proxies.
Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.
All it would take is for a major ISP in Utah to route everyone through a VPN, and boom, it's the same picture.
Yeah but the state of Utah could just tell them to knock it off because they're the state.
Isn't this kind of what Apple's Private Relay is?
Not when the definition of VPN is subjective. I could proxy/VPN through a friend's house and nobody would ever know it wasn't them.
A lot of law is adjudicated based on the intent, not the black-and-white definition. Proxying your traffic thru a friend's house (VPS in another location, etc) would be considered a "VPN" by a court. Definitional hacks, for the most part, don't fly with judges.
To handle the matter technically Utah would need a "great firewall of Utah" and a legislative mandate that all ISPs route thru it. Somehow they'd have to factor-in signals from cellular sites neighboring states and satellites.
This requires a lot of extra work though, and extra work is downward pressure on the behavior (underage people looking at pornography) that the state of Utah is trying to exert downward pressure on.
The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.
> The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.
So if you are legally required to block all VPN users and then fail to actually block all VPN users what is stopping you from being punished for not complying with the law?
Yes but isn't it suspicious that all your traffic goes to the friend's house and not to Facebook and Reddit? If you claim it is not a VPN does it mean your friend is providing illegal unlicensed hosting? That's even worse.
> does it mean your friend is providing illegal unlicensed hosting
Since when do you have to pull permits to put a server on the web?
"Suspicious" is not illegal, and neither is hosting.
Split tunnel is a thing, and in that instance the platform required to comply (like a porn site) doesn’t have any way to see all your traffic to determine if it’s a VPN/proxy connection or not.
You do not need to know "reliably". You can block everything remotely suspicious, and in case someone is blocked by mistake, they can file an application with all necessary documentation proving the connection is not a VPN.
Sounds like the great firewall of China. Pretty wild how much we are regressing in the states to say this out loud.
Let’s block traffic on the internet blindly just in case someone is looking at an adult website.
The church of LDS is no stranger to technical impossibilities
There are a category of things that are technically impossible until a burly man threatens to break your arm if you don't do them, and a category of things that are still impossible.
Doesn't help your arm, but when they're asking for things in that second category, it doesn't help them either.
But until you've broken their arm, you can't know which category you're in.
Wait, we're the burly man?
I've always aspired to be burly. This is great news.
weird when people make that swap without noticing it, huh?
>As we’ve said time and time again: the internet will always route around censorship.
Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.
Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.
Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.
The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.
Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.
The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"
My guess is if you are in China they can MITM you with their own root certs.
It's true unless we let freedom of speech and the press be interpreted narrowly, as the right to flap our jaws and to press paper against ink. That is up to us collectively.
Is China that successful at it lately? I see a lot of posters and info from China getting around the great firewall, and my understanding was that they don't really care if 1% of users do that so long as it mostly holds and only the technical minded or really fixated will see it.
So there is a route around censorship, but maybe the public doesn't really care about it.
There is also the difficult reality that the government doesn't need to block vpn entirely, but just make it a credible risk of being detected. If you have to worry about the state police barging into your home, you are likely to decide it isn't worth the risk and self-regulate.
I'm not sure whether it's 1% or 0.1% or only Xi Jinpin can access YouTube. China can adjust the surveillance level dynamically. It's a matter of cost and effect.
It's never been true.
The layer 2 and 3 of ISO/OSI stack does indeed "route around censorship". But the Internet as we know it is all Layer 7, and it's as centralized as it gets.
That's why regulators often aim straight at Layer 7 entities - companies providing consumer services over the web. Because no matter how unblockable the route between you and some server is, it doesn't mean anything when the server itself is refusing to talk to you.
What about p2p and less scrupulous actors like TPB? I guess in China the former is probably more effective but this sort of thing is immediately what I thought of when I read OP
Having the power of violence behind you makes technical hacks mostly irrelevant.
I’m pretty sure with Iran, and I assume other authoritarian nations, the state controls what traffic can and cannot leave their borders. When they go dark, they just effectively cut off access to the outside world entirely. Sure they may have their own state run servers that provide some services, but then they can inspect and manage all traffic being routed inside the country. Don’t have to try and find the VPN if there’s just no traffic.
I suppose Utah could impose some sort of strategy here, but would be so burdensome and anti-American I’m not sure they could pull it off. Instead of a blacklist of sites dictated by the site provider, you go the other way where all Utah ISPs maintain a whitelist of IPs permitted to Utah citizens. Any traffic attempting to reach a non-white listed IP, would be rejected.
It seems like Utah could do mostly do this by intercepting all consumer traffic.
Just buy the surveillance equipment from Russia and get it done.
With some sort of whitelist of IP addresses that consumers, travelers, and business executives are allowed to connect to while in the state?
A VPN/proxy could exist at almost any single address at any given time.
> Over the last two years, Iran officials warned that wider use of the satellite internet service could make communication controls within the country "ineffective", adding the regime has failed to produce an adequate policy response.
> “I sometimes joke that we might as well turn the Ministry of Communications and the Supreme Council of Cyberspace into amusement parks, because they will no longer serve any purpose,” Hakami said.
https://gulfnews.com/world/mena/iran-official-says-starlink-...
It's certainly less true than it was. It depends on how Matt Prince feels on any particular day.
To a large degree, most of the internet today is ultimately controlled by a few people. If what you have to say pisses off these people, and someone is determined to keep you off the internet, you have a problem. Kiwi Farms is a well known example, and continues to suffer under regular DDOS attacks. Regardless of how you feel about KF, it's undeniable that a) this nonsense has streissanded the site enormously and b) it's speech you don't like that needs protection.
Also there was the whole covid "misinformation" garbage fire... I certainly do not want my government or some megacorp to decide what can and can't say or read.
And going beyond the internet, I just want to remind you Americans, that your 1st amendment is almost unique (to my knowledge). Enjoy and protect your offensive, hateful, blasphemous, extremist, and deeply unpopular speech.
> It even went so far as to prohibit websites from offering instructions on how to use a VPN to bypass these checks
How is that not a blatant first amendment violation?
It is, but the first amendment isn't absolute.
In 1897 Indiana almost passed a law defining Pi as 3.2. These jurists have never cared about reality.
Wow, that is a wild read, thank you: https://en.wikipedia.org/wiki/Indiana_pi_bill
How is this impossible? DraftKings does it for California visitors.
DraftKings does it in a way that is good enough to comply with California law, which doesn't require perfection.
This Utah law requires perfection.
Why does it require perfection? The Utah law has a section on "Reasonable age verification methods" if I'm reading the right thing (EFF doesn't link to the law): https://le.utah.gov/Session/2026/bills/enrolled/SB0073.pdf , and it doesn't say a lot about geofencing other than the site shouldn't tell users how to circumvent it.
I know firsthand that DraftKings' geofencing checks go pretty far. They outright block every commercial VPN, and there are sketchy proxies that kinda get around it but then they want you to install some crap on a phone that reports location. Unfortunately know this from a gambler friend showing me.
I'm not in California and DraftKings blocks me connecting with a VPN, so they just don't seem to be distinguishing whether a VPN user is in California (which is the impossible part of this law).
they want to stop VPN traffic. If it's a plain IP address it's easy. VPN makes it hard.
I understand. You can't use DraftKings via a VPN.
What stops me from using DraftKings.com from a VPN? I'm at the page right now, but I don't have an account. Will they verify that my IP and home address match or something?
Since when do lawmakers cared about technical impossibilities?
Not sure what the impossibility is. VPN's have a set of exit relays. If traffic is coming from one of those exit relays, it's coming from a VPN, so adult websites can be required to block traffic from those exit relays. What am I missing?
The law requires blocking all VPN access.
It's impossible to have perfect knowledge of the entire set of VPN exit node addresses.
Sounds like a problem for those pesky, nasty porn websites, not a problem for the good christian lawmakers..
They're Mormons not Christians.
Members of the Church of Jesus Christ of Latter-day Saints are indeed Christian.
Mormonism is a branch of Christianity
According to Mormons
The law is only meant to apply to citizens of Utah though. Blocking all exit relays would mean that absolutely anyone accessing that website would not be able to do so from a VPN which burdens people outside of Utah too.
I would think that requiring adult websites to essentially block all VPN traffic to be pretty heavy handed and hardly a solution. Especially considering there are many reasons to use a VPN.
It's impossible to have a full and complete list of VPN exit nodes, for the simple reason that no company publishes the full list, and also technically if you set up an OpenVPN server on digital ocean and connect to that you're also using a VPN but no one would know your address is hosting a VPN server.
So it would be possible if the state demanded that VPN companies provide adult sites with continuously updated lists of their exit nodes.
It also seems to me like Utah could just demand that adult sites only accept traffic from residential ips.
You'd have to ask every non-residential host online to do the same. As above, you can get a DigitalOcean droplet and ssh -D to it, now you have a SOCKS proxy that for state's concern is doing the same as a VPN.
Utah could demand the moon, it doesn't mean that the federal government would agree they have a right to that demand.
Utah can't tell businesses that service the country (or the world) how to do anything in this regard. You can't demand a list of the VPN exit nodes, because no VPN would ever give you that, and if they're outside of your jurisdiction, how could you possibly enforce it (assuming you got the Feds to agree with your law regulating interstate/international commerce now). You can't tell websites to only accept residential traffic, for the same reasons.
The internet sorta fucks states rights (in a good way).
Why would a VPN company care about what Utah requires if they have no legal presence there(or in the US for that matter)?
Besides, there's no such thing as "residential" IPs. If I set a VPN gate at my mum's house, how would the porn company know?
The "impossibility" is in them saying "we cannot guarantee with 100% certainty that the user isn't using a VPN" and that's correct, they can't - but the law has no provision for that, they are risking fines over something they cannot control.