Reminds me of a funny story of how russian government faced the same paradox, and they solved it in the most elegant way, all foreign traffic equals VPN, so foreign traffic is essentially forbidden. Russian people outside of russia literallt can't access state services without a "reverse-vpn" now.<p>If you think they will stop at a mere "technical impossibility" I have bad news for you folks, they will just ban all the traffic they can't track, in Utah, UK, anywhere;)
> platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely<p>Is it even possible to reliably know that a connection is from a VPN? Anyone can proxy through a random hosting provider.
Requires the vpn provider to snitch and possible tag the ip frames or http frames lol<p>Folks would just host their own vpns various places and this would be pointless ….
It's all just an effort to control the 90%.
> Folks would just host their own vpns various places and this would be pointless<p>I think that’s the GPs point.<p>Though some services do already block traffic originating from popular hosting providers like AWS out of fears of bots.
You can do for free with tailscale exit nodes. Just have a friend in a different location host for you or buy some compute space somewhere
And some VPN "services" could use some compromised systems here and there.<p>Who is going to check anyway? You need significant technical leverage AND law leverage for the people doing that.
> Folks would just host their own vpns various places and this would be pointless<p>In the real world, very few people have that capability.
But also there's very little need today, it's very cheap to do, just complicated, a barrier that can be easily solved if there appears demand
Chinese people manage. Mostly by knowing someone who has the capability.
Do you have a friend/family out of state? Do they have a commodity router? Many have such a feature built in.<p>Less savvy individuals/business would also have no reason to obey these laws.<p>See <a href="https://en.wikipedia.org/wiki/Evil_bit" rel="nofollow">https://en.wikipedia.org/wiki/Evil_bit</a>
How many out of state friends and family would you feel comfortable asking to set up a VPN for you so you can watch porn?
The limitation isn't access to the technology. There is endless OSS, it's probably built into many standard OSes, and there are many available products and projects that will deploy the whole thing for you.<p>The limitation is technical skill, even having enough skill to know that this is a solution.
This is such a common HN trope, and it's tiresome.<p>Yes, lots of things will at any point be beyond the technical ability of most people as long as they remain niche. But as soon as a sizable market exists(e.g one created by a law, like in this case), products and services that close that gap will appear.<p>Hell, there's even stuff for doing this already, which is not <i>that</i> hard for non-technical people to set up, like Tailscale. I can easily imagine a Tailscale-like product that easily allows friends to use eachothers networks as a VPN with zero configuration or Wireguard knowledge required. I mean, when you think about it it's just Tailscale but more streamlined for that particular purpose.
Detection can be based on the IPs themselves, no packet tricks required. Plenty of services can do that: <a href="https://focsec.com/" rel="nofollow">https://focsec.com/</a><p>Now of course, if your VPN is a home-lab style VPN where you are connecting to a little wireguard box sitting in your own home, that is a totally different story.
Right, all you see is the IP address. And anyone in the world can set up an “individual” VPN just for them on a cheap VPS or cloud server anywhere else in the world. There’s no technical way to accomplish what they’ve mandated, only something approximating it like “block all connections from known commercial VPN services”.
Kinda.<p>I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)<p>I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying
That's not the same. You get blocked because the IP address you're coming from is associated with a VPN list, not because they're analyzing the traffic in detail.<p>The simplest methods block known datacenter IP ranges like you thought. More will score it based on several heuristics and a reputation over time. If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.
> If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.<p>Or, their so-called "smart" TV is acting as a proxy without their informed consent.
> If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.<p>In some parts of the world hiding (NAT) entire neighborhoods behind one public IP is normal practice.
Mozilla VPN runs on Mullvad who are transparent and publish active server and IP lists <a href="https://mullvad.net/en/servers.so" rel="nofollow">https://mullvad.net/en/servers.so</a> trivial to block them without blocking all of Azure/GCP/AWS[1]<p>There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.<p>The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).<p>Netflix are/were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.<p>[1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.
That list is the IPs users connect to. It is entirely distinct from the list of IPs the VPN traffic egresses from. I doubt believe that they publish their egress ranges.
Don’t think there was ever a time since Netflix started streaming where they only licensed global rights to shows. For their own originals they get global rights but the majority of their content is licensed and has always been slightly different in different territories.
My home internet is on a CGNAT, so I experience a lot of the same. Ironically, sometimes a VPN will get through.
The better question is can you ensure your traffic doesn't get funneled to utah? The answer is probably not. There is a huge nsa data center there... So it's not even a choice, it's do both impossible things.
maybe not reliably, but i was impressed by the effectiveness and sophistication of the GFW when i was traveling in China. ISP level filtering would likely also comply with the restrictions in this lawsuit.<p>It took quite a bit of finagling to bypass the GFW on my own and in some regions (Beijing) I was still randomly detected and throttled, it seemed.
Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.
It seems like withdrawing from Utah is the obvious option
As the article explains - this was not an option.<p>>SB 73 burdens the rights of all internet users outside of Utah because it requires adult websites to either know every visiting user’s physical location, and then block those in Utah, or to verify every visitor’s age just in case they might be in Utah. The law’s “actual-location provision in practice requires an entity to perform age verification services for every user visiting its site from any location because the entity would violate the law if even one of those users happened to be obfuscating,” the court wrote.<p>In order to withdraw from Utah, they would be forced to block traffic from everywhere since it's possible that some kid in Utah used a VPN to make it look like they lived in Singapore.
That was what the law attempted to do: Ban porn in Utah.<p>There is a very vocal anti-porn group in Utah. They do things like put up massive billboards that say "[Store name] sells porn." (Which is basically free advertising instead of shaming.)
Right, but if everyone serving porn did that (e.g., google image search, so I guess all of Google should ban Utah), then people would just send money out of state for vpn access, and probably remember the annoyance when it was time to vote.
The great firewall probes the host ip and if it suspects it is a vpn server (udp traffic etc) it just throttles to a halt the ip.<p>Tons of false positives, but they are non-domestic IPs so who (dares to) cares.
All it would take is for a major ISP in Utah to route everyone through a VPN, and boom, it's the same picture.
Yeah but the state of Utah could just tell them to knock it off because they're the state.
Well no, because the laws for ISPs and VPNs are different.<p>Most ISPs are already VPNs. Your connection is tunneled from your router at home, through some expansive DSL/ATM or GPON/PPPoE network, to a box at a data center that serves five neighborhoods with a single link by establishing a tunnel to each individual consumer router.<p>But the ISP has to make sure the geolocation databases have accurate information about it, and it has to retain logs of which user used which IP address at which time because the law says so. That's why it's not a "VPN".
Isn't this kind of what Apple's Private Relay is?
Literally every TLS connection could be flagged as being a VPN connection.
Many VPN providers have servers in many places. Anyone in the US can just use a server in Canada to bypass everything.
It's hard to find a proxy or VPN that isn't flagged as such. People pay extra for residential proxies.
I’ve been using different VPNs for years for work. I’m starting to come around to the value of a residential proxy service.<p>It’s starting to get annoying that things aren’t working. They’re shooting themselves in the foot though.<p>If they didn’t block VPNs, they would at least know what category to group them in.
TCP MSS < 1500 bytes can be a tell, although it will sometimes falsely identify non-"VPN" tunnels.
Of course it is. Half the services I try to access reject me with a notice saying they don't allow VPNs.
You do not need to know "reliably". You can block everything remotely suspicious, and in case someone is blocked by mistake, they can file an application with all necessary documentation proving the connection is not a VPN.
Not when the definition of VPN is subjective. I could proxy/VPN through a friend's house and nobody would ever know it wasn't them.
A lot of law is adjudicated based on the intent, not the black-and-white definition. Proxying your traffic thru a friend's house (VPS in another location, etc) would be considered a "VPN" by a court. Definitional hacks, for the most part, don't fly with judges.<p>To handle the matter technically Utah would need a "great firewall of Utah" and a legislative mandate that all ISPs route thru it. Somehow they'd have to factor-in signals from cellular sites neighboring states and satellites.
This requires a lot of extra work though, and extra work is downward pressure on the behavior (underage people looking at pornography) that the state of Utah is trying to exert downward pressure on.<p>The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.
Yes but isn't it suspicious that all your traffic goes to the friend's house and not to Facebook and Reddit? If you claim it is not a VPN does it mean your friend is providing illegal unlicensed hosting? That's even worse.
> does it mean your friend is providing illegal unlicensed hosting<p>Since when do you have to pull permits to put a server on the web?
If anybody is monitoring traffic patterns to this extent, it's not public knowledge. Even the NSA is unlikely to see traffic from one house to another in the same neighbourhood. And nobody except top terrorists gets prosecuted based on NSA intel because they have to reveal how they got the intel.
"Suspicious" is not illegal, and neither is hosting.
Split tunnel is a thing, and in that instance the platform required to comply (like a porn site) doesn’t have any way to see all your traffic to determine if it’s a VPN/proxy connection or not.
Why would that be suspicious?
> Is it even possible to reliably know that a connection is from a VPN?<p>No, it's not possible. You can only try to identify known protocols or suspicious patterns of data, timing or entropy. Theoretically, with a big enough collaboration, you could hide a VPN behind shaping traffic patterns and request order towards hundreds of different servers, and there's just no method of traffic analysis that can possibly identify that without prior knowledge.<p>Like, some firewalls try to identify an absence of connections outside the VPN, or an abnormal volume of data over a sustained period of time. But all that goes out the window when, say, you are connecting to hundreds of real servers at all times and only exchanging, say, basic HTTP requests with each one. For all they know you just have a million browser toolbars installed. They wouldn't know if the choice of request, order and timing encodes information because they wouldn't be able to prove what the client's intentions are in sending it or what the servers do with it.<p>If you tried to identify it, you would block every real connection.<p>I believe some VPN providers are beginning to play with things like this, but the problem is really that it's impossible to provide this. It only really works when you run it yourself, because that's the only way others don't know. So they're having to settle for compromises, like Mullvad's DAITA, which still uses a single server but tries to avoid showing tells of a VPN connection as opposed to something else like streaming.
The classic: ping the endpoint address, then “ping” the code. If the IP address comes back in 30ms but the JavaScript responds in 330ms, then the client is probably 300ms further away than they say they are claiming.
Or they’re on a computer that’s doing something intensive, swapping, or in low power mode. Or they have a browser extension that does stuff before scripts run. Or their cache is emptier than usual and they’re spending a long time doing an initial fetch of the latest ad tracking package your site installed. The list goes on. That’s far too noisy a signal to decide block-or-not based on. Good enough to try to sell someone faster gear, maybe, but not more than that.
This will also catch a SIM card in roaming, which is not a VPN.
except it is literally a VPN, actually. That's why it would have that characteristic. Except actually it wouldn't, because the test described only catches proxies at L4 and higher. It would catch a lot of CGNATs.
"As we've said time and time again: the internet will always route around censorship."<p>It won't route around self-censorship that arises out of surveillance<p>Nor will it take a stand against SNI which is a dead simple means of implementing censorship that's in widespread use every day for years
<i>> ... SNI which is a dead simple means of implementing censorship</i><p>Could you elaborate? What's "SNI", and how does it relate to censorship?
Nice try, bicycle-riding pelican.<p>I assume it's Server Name Indication, which sends hostnames in plain text. A better approach is Encrypted Client Hello, or ESNI (I'm not sure how they differ, probably like Betamax and VHS, one allows porn).
Doesn't it? I don't post on HN about smoking weed (that's self-censorship) but there are other places where you can post about it.
Sometimes HN commenters will try to argue in favor of SNI as if it's not possible to host multiple HTTPS sites on one IP address<p>It is possible<p>Consider all the sites hosted at 199.36.58.100 for example. Over 1,620 such sites have been submitted to HN in the past few years<p>ESNI is "Encrypted SNI", ECH is "Encrypted Client Hello". The Client Hello packet contains the SNI. For a time ESNI was available on all Cloudflare sites. Not anymore. ESNI, whatever its flaws, worked well enough that some censorship regimes blocked connections that used it. IMHO, ESNI and ECH are overcomplicated proposed solutions to a relatively simple problem: gratuitous use of SNI. For example, so-called "modern" browsers will send SNI to those 1,620+ sites even though it's not required<p>Alas, the people developing ESNI and ECH are not publishers or readers, the targets of censorship. They are "CDNs", hosting companies, intermediaries in the business of serving multiple HTTPS sites on single IP addresses. SNI has benefits for CDNs and costs for others
To big to fail social media is a problem for this
>As we’ve said time and time again: the internet will always route around censorship.<p>Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.<p>Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.<p>Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.
The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.<p>Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.<p>The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"
Yes China will kill your network connections. And that is proof that Internet cannot route around censorship. Any time Internet routes around censorship China finds a new way to censor it.<p>Normal people don’t care about “downgrade” or “decrypt” or “intercept” they care about availability.
My guess is if you are in China they can MITM you with their own root certs.
Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:<p><pre><code> 1. Make it illegal to distribute a browser that distrusts their CA
2. Make it illegal to run a browser that distrusts their CA
3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software</code></pre>
This is unnecessary, they already have the problem controlled better. They just outright block foreign services, and the domestic ones they can request data from freely.<p>Doesn’t require cracking crypto or any funny business around forcing people to install stuff.
Sure, a state <i>can</i> do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals <i>harder</i>; they can no longer do as much <i>surreptitiously</i>.
“Make it illegal to…” that has never in human history prevented anything from happening. Cannot increase the risk? Of course, but laws do not stop humans from humaning.<p>Furthermore, doing any of the things you listed would isolate all legitimate network traffic as well as any undesirable traffic, fully shuttering all Chinese manufacturing businesses from global requests via the web. This hat would happen then? Phone calls, emails, and even physical mail would become the new norm and most of the Chinese economy would collapse under the weight of not being able to hop on a Zoom with a client that wants tooling made for its aluminum manufacturing molds.<p>So besides my point of the black market your hypothesis of total control misses all the other pressures that exist that make what you’re proposing infeasible on its face. Only a place like North Korea that is willing to be a pariah state is old be willing to take the economic and social costs associated with your proposal, and they’ve only been able to do that because their abominable regime was in place before the internet existed and they pre-built controls very late in the game.<p>Tl;dr simply because a country _could_ do something doesn’t mean it’s realistic for reasons outside of basic networking concepts.
Useless. You still don't get the connection unless you trust the MITM. You either disable CT, or you don't get a connection.
Russia's ROSKOMNadzor has been trying to get users to install its own Root CAs in recent years. About 10 years ago everyone in the west removed CNNIC (Chinese counterpart) roots after they were caught MITM-ing.
> Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS<p>I mean... They could, though, no? If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.
> If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.<p>I'm sure that works in a Hollywood movie, in the same way you could reverse the polarity of the lasers to enable you to travel inside the computer from a household video projector, or decrypt all the world's telephone calls using a device built into your batmobile - but this isn't a Hollywood movie and so traffic isn't in fact "encrypted with a root cert".<p>If for any of a variety of reasons the Chinese authorities don't want your connection to exist they'll terminate the connection, exactly as I described in my earlier comment.
Is China that successful at it lately? I see a lot of posters and info from China getting around the great firewall, and my understanding was that they don't really care if 1% of users do that so long as it mostly holds and only the technical minded or really fixated will see it.<p>So there is a route around censorship, but maybe the public doesn't really care about it.
There is also the difficult reality that the government doesn't need to block vpn entirely, but just make it a credible risk of being detected. If you have to worry about the state police barging into your home, you are likely to decide it isn't worth the risk and self-regulate.
How I have heard it described is using a VPN in China is like smoking weed in the US. It’s widely done even if illegal and you’d have to be seriously unlucky to get in trouble. You’d at most get a warning.<p>People with more first hand experience can probably explain it better but it doesn’t seem that strict. China is not North Korea, their aims seem less about preventing people from learning about the world and more preventing non compliant foreign tech companies having Chinese users.
It absolutely is primarily about preventing people from learning about the world. You can’t run a system like China’s without controlling information. During the political meetings, they ramp up their blocking, and then they usually turn it down again after.<p>During the World Cup (2022, still zero covid in China), they started blurring out the crowd because people were noticing that nobody in the stands was wearing masks. They’d been told that the zero covid policy and draconian lockdowns were keeping them safe, and outside China was a Covid hell-hole. Protests followed four months later.<p>Nobody in China was told about western covid vaccines, much less allowed to get them.<p>VPNs aren’t widely used — there was a study posted here some months ago that estimated VPN use at around 1% of the population, too little to matter.<p>That’s why they’re a bit lax. They can afford to let some through to grease the wheels of commerce. You do have to be seriously unlucky to get into trouble.<p>(I was there during Covid, and some years before and after)
I'm not sure whether it's 1% or 0.1% or only Xi Jinpin can access YouTube. China can adjust the surveillance level dynamically. It's a matter of cost and effect.
I’m pretty sure with Iran, and I assume other authoritarian nations, the state controls what traffic can and cannot leave their borders. When they go dark, they just effectively cut off access to the outside world entirely. Sure they may have their own state run servers that provide some services, but then they can inspect and manage all traffic being routed inside the country. Don’t have to try and find the VPN if there’s just no traffic.<p>I suppose Utah could impose some sort of strategy here, but would be so burdensome and anti-American I’m not sure they could pull it off. Instead of a blacklist of sites dictated by the site provider, you go the other way where all Utah ISPs maintain a whitelist of IPs permitted to Utah citizens. Any traffic attempting to reach a non-white listed IP, would be rejected.
The internet will always route around censorship <i>in principled western nations</i>.<p>It's a politico-technological arms race. They make their laws. We make technology that completely nullifies their laws. They need to increase their tyranny in order to enjoy the same level of control they had before. The end state is either a totalitarian government or an uncontrollable population.<p>I used to think that we'd find some kind of equilibrium along the way, that we'd eventually discover the government's limits: some principle they refuse to break, some line they refuse to cross...<p>But the truth is these tyrants have no limits whatsoever. They'll stop at nothing in their quest to control the flow of information.
These are just aspirational statements, similar to "the internet always remembers" etc, they've never been true. And the passive voice is duly noted, it indeed depends mostly on those social forces for the "internet" to "act"/"route"
It seems like Utah could do mostly do this by intercepting all consumer traffic.
Just buy the surveillance equipment from Russia and get it done.
With some sort of whitelist of IP addresses that consumers, travelers, and business executives are allowed to connect to while in the state?<p>A VPN/proxy could exist at almost any single address at any given time.
It's never been true.<p>The layer 2 and 3 of ISO/OSI stack does indeed "route around censorship". But the Internet as we know it is all Layer 7, and it's as centralized as it gets.<p>That's why regulators often aim straight at Layer 7 entities - companies providing consumer services over the web. Because no matter how unblockable the route between you and some server is, it doesn't mean anything when the server itself is refusing to talk to you.
> nations like Iran and China have progressed the state-of-the-art and playbook<p>That’s a rather shallow and naive perspective. I’ll try to keep this short, but the overt blocking oriented “censorship” ascribed to China, Iran, or Israel is actually not at all “state-of-the-art”, it’s an inherent rather coarse approach to censorship.<p>If you want the true “state-of-the-art“ you can look no farther than the USA, where the “state-of-the-art” is such that people don’t even realize it’s censorship, let alone that anything is happening at all.<p>China, Iran, or Israel may or may not engage in censorship at a kind of high level that is apparent and observable; however the censorship in the USA and by extension in its various vassals of its empire, is far more sophisticated and base level to such a degree that the system, the whole society is the censorship mechanism, censorship is not something done to the system, the system is the censorship. That is “state-of-the-art”!
It's true unless we let freedom of speech and the press be interpreted narrowly, as the right to flap our jaws and to press paper against ink. That is up to us collectively.
> Over the last two years, Iran officials warned that wider use of the satellite internet service could make communication controls within the country "ineffective", adding the regime has failed to produce an adequate policy response.<p>> “I sometimes joke that we might as well turn the Ministry of Communications and the Supreme Council of Cyberspace into amusement parks, because they will no longer serve any purpose,” Hakami said.<p><a href="https://gulfnews.com/world/mena/iran-official-says-starlink-could-cripple-tehrans-internet-control-playbook-1.500694244" rel="nofollow">https://gulfnews.com/world/mena/iran-official-says-starlink-...</a>
There will always be >0 people who find a way around censorship, that's about it. It's not bad AND ineffective, that's a contradiction.
It's certainly less true than it was. It depends on how Matt Prince feels on any particular day.<p>To a large degree, most of the internet today is ultimately controlled by a few people. If what you have to say pisses off these people, and someone is determined to keep you off the internet, you have a problem. Kiwi Farms is a well known example, and continues to suffer under regular DDOS attacks. Regardless of how you feel about KF, it's undeniable that a) this nonsense has streissanded the site enormously and b) it's speech you don't like that needs protection.<p>Also there was the whole covid "misinformation" garbage fire... I certainly do not want my government or some megacorp to decide what can and can't say or read.<p>And going beyond the internet, I just want to remind you Americans, that your 1st amendment is almost unique (to my knowledge). Enjoy and protect your offensive, hateful, blasphemous, extremist, and deeply unpopular speech.
Fascism is on the march. Dirty pictures aren't the real reason governments want this level of control over the internet. You can be sure that we'll see worse. Glad we won this battle.
Can someone explain why it wouldn't work to have porn companies use only certain domains, and filter based on those domains, if people are so intent on blocking it?
The smart version of this is that adult content providers send a header or something with every response that contains NSFW, and then you use parental controls on client devices to not show those responses. This even works for sites that show a mix of kid-friendly and adult content <i>cough reddit cough</i>. It offers fewer opportunities for general purpose censorship, though, so there's less interest.
The US Congress evaluated [1] the legality of forcing adult websites onto certain TLDs in the 2000s and it was determined to be legally ambiguous and would almost certainly face substantial 1st amendment challenges. So they didn't pursue it.<p><a href="https://www.everycrsreport.com/files/20080714_RL33224_1e6b938ac811728e431489084d35dc26e4e8c720.html" rel="nofollow">https://www.everycrsreport.com/files/20080714_RL33224_1e6b93...</a>
Because you shouldn't get behind a thing that shouldn't exists. Technical solutions to societal problems are and will always be naught and fraught with unnecessary jump roping. In this case, the content itself isn't dangerous, what is dangerous is consuming it without the correct context, ie. education.
What's the enforcement mechanism if some porn company in Elbonia "forgets" and uses hothothot.el, instead of hothothot.porn?
also the whole point of having .el is to be outside US jurisdiction so the US can't mess with their domains except for cutting off the whole country (which would splinter the internet).
Here my genius self sits, momentarily wondering what M-x hothothot does in Emacs.
A Utah state organ sues them in Utah court, obviously.
> It even went so far as to prohibit websites from offering instructions on how to use a VPN to bypass these checks<p>How is that not a blatant first amendment violation?
Businesses (despite common belief) have less free speech power when engaging in commerce. If they said, "Utah law XYZ violates the constitution, call your state legislator", almost certainly protected. Versus: "Here are instructions on how to violate the law" (whether eventually upheld or not), much less sturdy ground.
Because we don’t like people doing it. Duh.
Rice v. Paladin Enterprises, it isn’t automatically first amendment protected to tell people how to effectively commit crimes. It isnt open and shut, but the first amendment isn’t a get out of jail free card.
It is, but the first amendment isn't absolute.
I guess this could be speech integral to criminal conduct but seems like a stretch.
It is, but our judges and legislators find it expedient to pretend it's not.
The people who wrote it and the people who ratified didn't seem to think it was absolute. The First Amendment was not intended to create a new right of speech. It was intended to prevent the new federal government from abridging the existing right as it was under common law and state law.<p>Under state and common law at the time many kinds of speech were routinely regulated or even criminalized, such as defamation and blasphemy.
They weren't short on ink. If they wanted to add additional conditions and tweaks, they would have. What they thought, or what they wrote down elsewhere, doesn't matter.<p>Or at least it shouldn't.
The constitution did not apply nationally originally, it only applied to the federal government.<p>It wasn't until the 14th amendment that the constitution started overriding state constitutions/laws.<p>Idaho did in fact add additional ink to the freedom of speech [1]. In fact this is why so many states have a bill of rights similar to the federal constitution in their own constitutions.<p>[1] <a href="https://legislature.idaho.gov/statutesrules/idconst/ArtI/Sect9/" rel="nofollow">https://legislature.idaho.gov/statutesrules/idconst/ArtI/Sec...</a>
Indeed they were not short of ink, so if they wanted to create some sort of free speech right that differed from what people at the time (including themselves) understood "freedom of speech" to mean they would have used a different term and explained the scope of the new right.
I'm not looking to get into a debate on the law just curious why these websites can't force accounts for everyone just like the gambling sites do.
Gambling sites require an account because they need to know who placed the bet, who to charge for the bet, and where to send the money when you win.<p>A porn site does not.
Same burdensome provision issue? Forcing everyone outside of Utah to do something just in case they're from Utah.
> why these websites can't force accounts for everyone<p>Idk why people think it’s a good idea to force everyone to provide their id to jerk off.
It's so that, when judgement day comes, our Lord Jesus Christ of Nazareth has a concrete record of what you've been doing with your semen. It's very important, you see. God's work, even.
They can, but any friction here means less ad revenue, as people will just go to a site with less friction
They definitely can
Since when do lawmakers cared about technical impossibilities?
Remember to renew your support for the EFF. They take on some interesting cases
> Utah's VPN law demands a technical impossibility<p>How does legislation work in the US? How can an impossible law pass? Is it just some boomer stomping his feet like a toddler "I know what I want, and I want it now" without consulting any technical experts, and then private organizations like the EFF and courts have to clean up the mess?
I think ultimately we're headed for locked device attestation for age and physical location, and legislation like this is going to be a driving force. If that wasn't bad enough, I think most people are ultimately in favor of this. The future is bleak.
Is there actually any jurisdiction in which technocrats have veto power over legislation?
It's not about veto power, it's about consulting technical experts to evaluate whether the legal proposal even makes sense. The EU Cyber Resilience Act is a good example: experts stepped in and made sure that the term "supplier" was accurately defined so some random Joe Shmoe could not be held liable for bugs in some piece of code he threw over the wall on GitHub. The law still got passed, but after being refined.
<i>> it's about consulting technical experts to evaluate whether the legal proposal even makes sense</i><p>And that often comes down to people realising that they need to engage those experts. Instead many just assume "it makes sense to me, with the thinking I've done about it" means that it definitely actualy makes sense.<p>Also sometimes the very cynical view is true: people <i>know</i> technical experts will pick holes in something, so they find a way to rush it through quickly to not allow the chance for that. Sometimes they are quite honest about this with arguments based in "not letting perfect be the enemy of good". Once a rule is in place it then becomes someone else's problem to undo it, or at least fix the technical problems in-place. Meanwhile those that got it through get credit from those who agree with the emotive argument, and also don't care about the technical details & accidental implications, credit that they can try use to further the cause or their career.
What if the technical experts tell the legislators something they don’t want to hear? Do you think the legislators will just go along with a bunch of egghead nay-sayers? Their constituents/donors/special-interests are demanding action!
What makes you think an "expert" was not consulted on this? Experts can be wrong too, regardless of credentials. That's why AI should be used to review and critique all new laws going forward, in order to prevent such mistakes from being made law. Hard /s, btw.
How is this impossible? DraftKings does it for California visitors.
DraftKings does it in a way that is good enough to comply with California law, which doesn't require perfection.<p>This Utah law requires perfection.
Oh I see, "An individual is considered to be accessing the website from this state if the individual is actually located in the state regardless of whether the individual is using..." as mentioned in the injunction <a href="https://www.courthousenews.com/wp-content/uploads/2026/09/aylo-freesites-utah-division-consumer-protection-opinion.pdf" rel="nofollow">https://www.courthousenews.com/wp-content/uploads/2026/09/ay...</a> So yeah the law would basically require everywhere to perform age verification, where the law says it only has to be "commercially reasonable."
I'm not in California and DraftKings blocks me connecting with a VPN, so they just don't seem to be distinguishing whether a VPN user is in California (which is the impossible part of this law).
they want to stop VPN traffic. If it's a plain IP address it's easy. VPN makes it hard.
In 1897 Indiana almost passed a law defining Pi as 3.2. These jurists have never cared about reality.
Wow, that is a wild read, thank you: <a href="https://en.wikipedia.org/wiki/Indiana_pi_bill" rel="nofollow">https://en.wikipedia.org/wiki/Indiana_pi_bill</a>
They seem to know what they're doing here. A website can comply as long as they perfectly geofence (impossible) or do "reasonable" age verification. "Reasonable" only for the latter. So they basically want these sites in any US state to do age verification.
> Section 47. No person having one-eighth part or more of negro blood shall be permitted to marry any white woman of this State, nor shall any white man be permitted to marry any negro woman, or any woman having one-eighth part or-more of negro blood, and every person who shall knowingly marry in violation of the provisions of this section, shall, upon conviction thereof, be imprisoned in the State’s prison not less than one, nor more than ten years, and be fined not less than one thousand nor more than five thousand dollars.<p><a href="https://www.pastpaperhero.com/resources/state-v-gibson-36-ind-389-ind-1871" rel="nofollow">https://www.pastpaperhero.com/resources/state-v-gibson-36-in...</a><p>This law did not "almost pass" but actually passed and remained in force till 1967.<p>You think they wouldn't try to fuck with pi?
I'm not sure your claim is backed up by the evidence you've provided (to wit, that Indiana <i>did not</i> pass the bill).
If you want to ban ISP's in your state, or build a state firewall, or arrest your citizens, you are welcome to do so - but what happens on servers outside your state that your state is choosing to connect to is clearly none of your business.<p>Seems like we need a fundamental challenge to the concept that you have any jurisdiction whatsoever.
Being able to tie an IP to a rough physical location was, in retrospect, a huge Internet design mistake. IPs should be like random UUIDs. They should have been designed to get assigned randomly when you obtain one, rotated / thrown away periodically, with no hierarchical numeric relationship with the ISP that is assigning them.
It was much easier to assign blocks of IPs to an ISP rather than a 4.3B line lookup table. And how would you ensure that an address has been rotated? How do you determine who the real owner of an IP is when collisions occur? You're asking for a worldwide atomic database propagated to all routers in the days where a 32bit number was considered massive.
It's not practical because IPs are routed in blocks, and this is necessary for efficiency. Otherwise every single router on the internet would have to remember the locations of up to 100 billion connections, and when the internet surpasses this size every router will need to be replaced.
I mean, in some cases it seems alright to want to try to prevent VPN usage (in certain scenarios).<p>Utah is one of a few states that bans gambling. It is logically consistent for them to want to prevent people from using VPNs while in Utah to get around that to do things like access gambling websites, sports books, or prediction markets.<p>That said, it is fairly difficult (and almost impossible for self-made VPNs/tunnels...). The court was right, but it kind of sucks for Utah in this case. They should have the right in some way to uphold their gambling laws.<p>Sorry, but if you haven't seen how bad some people and places can be when it comes to that stuff, you probably won't get why.<p>EDIT: HN is ratelimiting my ability to reply to replies again, for some reason, so my response follows:<p>Yes, but they have the uncomfortable reality of having to police (I mean in the classical, community way, not an Orwellian way) the results of it -- with resources that are scarecely available, or unavailable. Crime goes up, domestic violence increases, rowdiness and noise complaints go up, fights increase, addiction increases, money problems and lenders get involved....<p>I never liked social issues being called "public health" issues but in some cases, where things are literally outlawed and more than a certain amount of people with certain predilections take advantage of opportunities to skirt the law more than a few times, it sort of becomes so...<p>Which usually means less other kinds of freedoms for the rest of the people in that location. Some places I have lived with large online gambling populations have been frankly disturbing.
If you are rate limited it's because the algorithm believes you are a person who habitually spams bad content. Accounts start out un-limited. Once an account is limited it is not possible to get un-limited.
> The court was right, but it kind of sucks for Utah in this case. They should have the right in some way to uphold their gambling laws.<p>They still have the right to legislate, just not the technical capability to enforce.
> Yes, but they have the uncomfortable reality of having to police the results of it<p>I'm not against adding some friction to certain behavior deemed undesirable by society, but at the end of the day people are going to do what they will. Vice predates the Internet by thousands of years and will not and can not be "solved" by technical means.
[flagged]
[dead]
[flagged]
[dead]
[dead]
[flagged]
There are a category of things that are technically impossible until a burly man threatens to break your arm if you don't do them, and a category of things that are still impossible.<p>Doesn't help your arm, but when they're asking for things in that second category, it doesn't help them either.
But until you've broken their arm, you can't know which category you're in.
I remember talking about voting fraud with an indian friend. He said it was more overt in india - a burly guy would grab your finger and make it press the "correct" voting machine button.
No stranger to expecting to apply their morality to all people, even those who have a very different set of beliefs. Just a niche brand of christian nationalism seeking to subjugate everyone to their ways.
Huh? Is this comment referring to something specific or is it just a general swipe at a religion that's unliked around here?
I think "The Church" (The Church of Jesus Christ of Latter-Day Saints) is trying to keep Pornhub from publishing stats of how many ~people~ ~righteous Church members~ Melchizedek Priesthood holders are whacking to "cosplay porn" and "lesbian porn".
Not sure what the impossibility is. VPN's have a set of exit relays. If traffic is coming from one of those exit relays, it's coming from a VPN, so adult websites can be required to block traffic from those exit relays. What am I missing?
The law is only meant to apply to citizens of Utah though. Blocking all exit relays would mean that absolutely anyone accessing that website would not be able to do so from a VPN which burdens people outside of Utah too.
This is what I was missing. Demanding that porn sites block VPN traffic (or only accept residential traffic) would mean that everyone everywhere using a VPN gets blocked not just in Utah.<p>I still suspect there's some kind of solution. Like Utah could tell VPN providers that if they service a customer in Utah then the VPN provider can't route traffic to adult sites. Or put the burden on the VPN provider to do age verification if porn is gonna be available through the VPN.<p>Come to think of it, I'm still a bit confused as to why VPNs are even relevant because it would seem to me that age verification would be done through some kind of having-credit-card type scheme which VPNs are entirely irrelevant to. I even read the article and I'm still confused. Oh well.
VPNs are relevant because Utah only has the power to require ages verification in Utah, and a VPN allows someone to pretend they're not in Utah.
You can mail cash to mullvad.
<p><pre><code> The law likely violates the U.S. Constitution’s prohibition on passing laws that significantly burden businesses and people outside Utah’s borders.
SB 73 burdens the rights of all internet users outside of Utah because it requires adult websites to either know every visiting user’s physical location, and then block those in Utah, or to verify every visitor’s age just in case they might be in Utah.
</code></pre>
It's technically impossible to both implement Utah's law and respect the constitution. To make it technically feasible you'd need to either change the constitution or federalize the law.
<a href="https://le.utah.gov/~2026/bills/static/SB0073.html" rel="nofollow">https://le.utah.gov/~2026/bills/static/SB0073.html</a><p>| An individual is considered to be accessing the website from this state if the individual is actually located in the state, regardless of whether the individual is using a virtual private network, proxy server, or other means to disguise or misrepresent the individual's geographic location to make it appear that the individual is accessing a website from a location outside this state.<p>But how can any site check if a client is a) a VPN client (typically this can be known because VPN exit node IPs can be learned), __and__ b) in Utah?<p>The impossibility lies in (b). Effectively this forces any affected companies having a nexus to the state of Utah to forbid VPN clients. I think that's a bit too far-reaching. It would be much more practicable instead to ask VPNs to disallow Utah client exits to affected sites w/o age checks -- VPN services aren't free, so VPNs basically can do age checks.<p>Given that this could have been written to be feasibly implemented, either this text was written to cause a controversy, or this text was written by people who don't know how things work. Either way, this text cannot be enforceable as written. The Utah legislature can easily modify this to be enforceable (see above), so it's not like a court striking this down might be playing partisan games just by striking it down.
The law requires blocking all VPN access.<p>It's impossible to have perfect knowledge of the entire set of VPN exit node addresses.
I would think that requiring adult websites to essentially block all VPN traffic to be pretty heavy handed and hardly a solution. Especially considering there are many reasons to use a VPN.
Probably that “all VPNs” and all commercial VPN providers are two vastly different things. You can literally just make your own VPN if you have access to hosts on two different networks.
It's impossible to have a full and complete list of VPN exit nodes, for the simple reason that no company publishes the full list, and also technically if you set up an OpenVPN server on digital ocean and connect to that you're also using a VPN but no one would know your address is hosting a VPN server.