A court order about one US state's adult-site rules drew 266 points and 120 comments on Hacker News by the time MrKeyoor's brief captured it. Utah had turned perfect geolocation into a product requirement, then attached liability to a single miss even though websites had no technical way to pass the test.
US District Judge David Barlow has now paused the location provisions of Utah's SB 73 while a lawsuit brought by Aylo Freesites proceeds. The preliminary injunction is temporary, and it does not erase the state's wider age-verification law. It does establish a useful limit for anyone writing internet policy: software cannot reliably recover information that a privacy system was designed to hide.
The requirement a VPN is built to defeat
Utah's Online Age Verification Amendments treat a visitor as accessing a covered site from Utah when the person is physically there, even if a VPN, proxy, or another tool makes the connection appear to come from somewhere else. The law also bars covered sites from facilitating or encouraging the use of a VPN to get around age checks, including by providing instructions.
That first provision shifts an age check into a location problem. A conventional IP lookup can estimate where the visible endpoint sits. With a VPN, the visible endpoint is the VPN server. A site may see an address in another state or country while the person behind the tunnel is in Utah. The origin is absent from the ordinary request, so adding a larger database does not restore it.
This distinction matters because SB 73 made the visitor's actual physical location the fact that controls liability. According to the court's order, a site could violate the law if even one person hid a Utah location. Barlow described the result as strict liability for determining users' locations. The site has to be right every time while a visitor needs to evade detection once.
The court did not have to imagine the operational response. A covered service could block Utah or reject traffic from known VPN endpoints. It could also age-check every visitor in case that person was concealing a Utah connection. Aylo already blocks its sites in Utah under an earlier agreement, KSL reported. The expanded rule still asked the company to identify Utah users who appeared to be elsewhere.
Proposed detection collected more data without finding certainty
Utah's proposed implementation rules tried to close the gap with signals around the connection. In comments filed with the Utah Department of Commerce, the Electronic Frontier Foundation said the proposed system could examine latency, device or browser time zones, and other data sent by the device. EFF is an advocacy group opposing the rule, but its engineering objection is concrete: network congestion changes latency, while a time zone is easy to alter and does not prove where a device sits.
Those signals can produce a risk score. They cannot produce a physical address with zero error. Routing protocols, an ISP's setup, poor cellular coverage, and ordinary congestion can change latency without showing that someone is evading an age gate. A time-zone mismatch may look suspicious, yet the setting itself remains weak evidence of physical location.
A detection system also changes the privacy cost for people who never use a VPN. To decide whether an incoming visitor is hiding a Utah location, a service first has to inspect that visitor's network and device signals. EFF argued that this would push sites toward active collection across their whole audience, including people outside Utah who had no reason to expect a state rule to shape the request.
The proposed rules also contemplated a safe harbor and a way to challenge incorrect age results. EFF's filing said the error targets were infeasible to guarantee and the appeals language lacked a resolution time. That combination leaves a familiar production problem: the site must act on a probabilistic classifier, but the legal standard behaves as though the classifier were deterministic.
Why a Utah rule affected every visitor
Barlow found that Aylo was likely to succeed on its claim that the location provisions improperly burdened activity outside the state. The ruling says the practical effect would be age verification for every visitor because any one of them might be concealing a Utah location. It also points to less burdensome ways for the state to pursue its stated aim of keeping minors away from adult material.
Two short lines in the order carry most of the technical weight. The statute required covered services to geolocate users "with perfection," while "geolocation perfection is not presently possible." The finding matters more than whether today's VPN blocklists are good or poor. Even a much better classifier would still have false positives and false negatives. A law that punishes any miss leaves no passing score below 100 percent.
The timing put the compliance question within days of becoming real. Utah published its proposed rules on September 1 and said they could take effect as soon as October 8, according to EFF's account. Barlow's order prevents enforcement of the location provisions while the court considers what comes next.
The injunction is narrower than some of the reaction around it. Aylo did not challenge the provision that prevents covered websites from sharing information about VPNs, EFF reported. That speech restriction therefore remains outside this order. The underlying case also continues, so the judge has not issued a final decision on every part of SB 73.
Utah may revise the law rather than abandon the policy. State senator Calvin Musselman, who sponsored SB 73, told KSL that he respected the decision and might adjust the location language in the next legislative session. He maintained that the goal is to stop minors from using VPNs to avoid age gates. The open question is whether a rewrite accepts measurable error or simply describes perfect detection in different words.
A product requirement needs a possible success state
For developers, the order is a reminder that legal requirements eventually become a ticket, then rejection paths in code and records in a database. "Determine actual physical location despite deliberate obfuscation" cannot be implemented as written. A vendor can sell an estimate. A service can combine IP reputation with device signals. Neither method can reveal a fact that the connection does not reliably disclose.
The fallback choices carry their own costs. Blocking every VPN endpoint denies access to people using privacy and security tools for ordinary reasons. Verifying every visitor's age expands identity handling far beyond the state. Device fingerprinting adds another collection layer, then creates records that need access controls and a deletion policy. Each workaround changes the system without satisfying the original demand for certainty.
The Utah order can be applied beyond adult websites. Any jurisdiction-specific rule about a user's age or permitted access depends on how accurately a service can determine who and where that person is. When the identifier is missing or intentionally masked, enforcement can spill across borders and onto users the rule was never meant to reach.
Watch the docket for an appeal or final ruling, then compare any legislative rewrite with the engineering problem Barlow identified. A workable version would need an attainable standard and an explicit treatment of mistakes. It would also have to limit the extra data collected from everyone else. If the next draft still makes one hidden Utah connection a violation, the same impossible test will remain under a new set of words.