There are a category of things that are technically impossible until a burly man threatens to break your arm if you don't do them, and a category of things that are still impossible.
Doesn't help your arm, but when they're asking for things in that second category, it doesn't help them either.
I remember talking about voting fraud with an indian friend. He said it was more overt in india - a burly guy would grab your finger and make it press the "correct" voting machine button.
No stranger to expecting to apply their morality to all people, even those who have a very different set of beliefs. Just a niche brand of christian nationalism seeking to subjugate everyone to their ways.
Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.
Yes but isn't it suspicious that all your traffic goes to the friend's house and not to Facebook and Reddit? If you claim it is not a VPN does it mean your friend is providing illegal unlicensed hosting? That's even worse.
Split tunnel is a thing, and in that instance the platform required to comply (like a porn site) doesn’t have any way to see all your traffic to determine if it’s a VPN/proxy connection or not.
If you cannot determine the traffic type, you can block it and wait until someone appears with proper documentation and explains what they were sending.
That's what the judge agreed with: it's unreasonable to require you to block all Internet traffic with the assumption it's all VPN traffic until proven otherwise.
Under Utah's law as written, a private business has to assume any single IP address could be operating a VPN/proxy.
This requires a lot of extra work though, and extra work is downward pressure on the behavior (underage people looking at pornography) that the state of Utah is trying to exert downward pressure on.
The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.
> The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.
So if you are legally required to block all VPN users and then fail to actually block all VPN users what is stopping you from being punished for not complying with the law?
A lot of law is adjudicated based on the intent, not the black-and-white definition. Proxying your traffic thru a friend's house (VPS in another location, etc) would be considered a "VPN" by a court. Definitional hacks, for the most part, don't fly with judges.
To handle the matter technically Utah would need a "great firewall of Utah" and a legislative mandate that all ISPs route thru it. Somehow they'd have to factor-in signals from cellular sites neighboring states and satellites.
I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)
I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying
Mozilla VPN runs on Mullvad who are transparent and publish active server and IP lists https://mullvad.net/en/servers.so trivial to block them without blocking all of Azure/GCP/AWS[1]
There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.
The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).
Netflix are/were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.
[1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.
That list is the IPs users connect to. It is entirely distinct from the list of IPs the VPN traffic egresses from. I doubt believe that they publish their egress ranges.
That's not the same. You get blocked because the IP address you're coming from is associated with a VPN list, not because they're analyzing the traffic in detail.
The simplest methods block known datacenter IP ranges like you thought. More will score it based on several heuristics and a reputation over time. If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.
You do not need to know "reliably". You can block everything remotely suspicious, and in case someone is blocked by mistake, they can file an application with all necessary documentation proving the connection is not a VPN.
We should also restrict access to foreign fake news websites that spread destabilizing propaganda. We can include an exception for academics, and thus will require a new accreditation and licensing scheme for them. Naturally we will then want to implement common sense guardrails for their conduct ... /s
They don't care about porn. The people who would vote for it in Utah do, and that's why Utah is being used as a vehicle by other people to bolster the need to root all computers.
How can you be that paranoid about one thing and so gullible with another? We’re surrounded by phones, cameras, smart cars, IoT, microphones and most people are on social media too.
The government demonstrably has the ability to break into your comms and data without going through any of this. Instead of a libertarian conspiracy theory have you considered that politicians chase power and re-election?
Taking a stand and making major changes is hard to pull off, costs a lot of political resources, and can backfire horribly. Doing symbolic, popular crap that’s popular with the (admittedly thick and ignorant) majority is an easy win. Moral outrage is an easy win. “Think of the children” is an easy win.
Assuming you are really asking, the two largest objections:
- religious/cultural. My beliefs forbid this, it makes people bad/worse in some hard-to-define way, so no one should be allowed to do it. Sometimes with an emphasis that the sellers are luring good people into sin/ruin.
- it harms women. Many of the participants are trafficked or coerced in some way (and further abused). The profits from the industry encourage more of this. It “warps” the mind of men who use it, leading them to mistreat and abuse women.
I see elements of truth in all these, but IMO they are ultimately not compelling, prohibition is unworkable and unduly infringes on willing participants and consumers.
Frankly I believe the whole “warps the mind of men to abuse women” is total nonsense.
I’ve watched plenty of porn in my life, probably a bit more than average. I’ve never done anything out of the norm or unwanted to woman, let alone abuse one.
I think shitty people will be shitty people and it’s just a really easy thing to point at instead of taking responsibility for it. It’s also a convenient plausible sounding correlation for people who already want to ban porn to use.
Agreed. It’s like the argument that video games cause shooters.
Umm, I played plenty of GTA growing up and I’ve never stolen a car. People are actually very good at separating fantasy from reality, believe it or not.
This is not the claim. The claim is that, empirically, many (or enough) of the women who end up in porn are underage, trafficked, or psychologically coerced (due to poverty, drug addiction, abuse, etc) such that the choice is not really the free choice of willing participant.
I am all for individual freedoms, but I've read enough about this issue, and seen enough documentaries, that I think the claim is very well-founded. Of course, some porn stars are just willing adults who doing something they want to do, but there are many who are not.
That's one reason why traditionists in power usually crack down on any sort of pornography or alternate sexuality. Sex is a huge driver for human behavior. And established power structures would prefer that the only way for anyone to get sex is via compliance with the existing power structures. It's not something where the establishment is ever going to be able to perfectly control things, but if they can make it more difficult to get any sort of sexual gratification that doesn't align with their preferred social structure that gives the establishment an advantage in holding on to power.
Ofcom is investigating PornHub even after PornHub installed age checks as Ofcom claims age checks not “robust” (read: VPN ban). So hand over your id to see porn.
Detection can be based on the IPs themselves, no packet tricks required. Plenty of services can do that: https://focsec.com/
Now of course, if your VPN is a home-lab style VPN where you are connecting to a little wireguard box sitting in your own home, that is a totally different story.
The limitation isn't access to the technology. There is endless OSS, it's probably built into many standard OSes, and there are many available products and projects that will deploy the whole thing for you.
The limitation is technical skill, even having enough skill to know that this is a solution.
The classic: ping the endpoint address, then “ping” the code. If the IP address comes back in 30ms but the JavaScript responds in 330ms, then the client is probably 300ms further away than they say they are claiming.
That was what the law attempted to do: Ban porn in Utah.
There is a very vocal anti-porn group in Utah. They do things like put up massive billboards that say "[Store name] sells porn." (Which is basically free advertising instead of shaming.)
Right, all you see is the IP address. And anyone in the world can set up an “individual” VPN just for them on a cheap VPS or cloud server anywhere else in the world. There’s no technical way to accomplish what they’ve mandated, only something approximating it like “block all connections from known commercial VPN services”.
> Is it even possible to reliably know that a connection is from a VPN?
No, it's not possible. You can only try to identify known protocols or suspicious patterns of data, timing or entropy. Theoretically, with a big enough collaboration, you could hide a VPN behind shaping traffic patterns and request order towards hundreds of different servers, and there's just no method of traffic analysis that can possibly identify that without prior knowledge.
Like, some firewalls try to identify an absence of connections outside the VPN, or an abnormal volume of data over a sustained period of time. But all that goes out the window when, say, you are connecting to hundreds of real servers at all times and only exchanging, say, basic HTTP requests with each one. For all they know you just have a million browser toolbars installed. They wouldn't know if the choice of request, order and timing encodes information because they wouldn't be able to prove what the client's intentions are in sending it or what the servers do with it.
If you tried to identify it, you would block every real connection.
I believe some VPN providers are beginning to play with things like this, but the problem is really that it's impossible to provide this. It only really works when you run it yourself, because that's the only way others don't know. So they're having to settle for compromises, like Mullvad's DAITA, which still uses a single server but tries to avoid showing tells of a VPN connection as opposed to something else like streaming.
>As we’ve said time and time again: the internet will always route around censorship.
Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.
Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.
Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.
Is China that successful at it lately? I see a lot of posters and info from China getting around the great firewall, and my understanding was that they don't really care if 1% of users do that so long as it mostly holds and only the technical minded or really fixated will see it.
So there is a route around censorship, but maybe the public doesn't really care about it.
There is also the difficult reality that the government doesn't need to block vpn entirely, but just make it a credible risk of being detected. If you have to worry about the state police barging into your home, you are likely to decide it isn't worth the risk and self-regulate.
I'm not sure whether it's 1% or 0.1% or only Xi Jinpin can access YouTube. China can adjust the surveillance level dynamically. It's a matter of cost and effect.
That's the way it was explained to me. Letting the fringe do what they're going to do anyway while inoculating the majority to outside influence is the goal and the difficulty setting is dynamic.
I’m pretty sure with Iran, and I assume other authoritarian nations, the state controls what traffic can and cannot leave their borders. When they go dark, they just effectively cut off access to the outside world entirely. Sure they may have their own state run servers that provide some services, but then they can inspect and manage all traffic being routed inside the country. Don’t have to try and find the VPN if there’s just no traffic.
I suppose Utah could impose some sort of strategy here, but would be so burdensome and anti-American I’m not sure they could pull it off. Instead of a blacklist of sites dictated by the site provider, you go the other way where all Utah ISPs maintain a whitelist of IPs permitted to Utah citizens. Any traffic attempting to reach a non-white listed IP, would be rejected.
The layer 2 and 3 of ISO/OSI stack does indeed "route around censorship". But the Internet as we know it is all Layer 7, and it's as centralized as it gets.
That's why regulators often aim straight at Layer 7 entities - companies providing consumer services over the web. Because no matter how unblockable the route between you and some server is, it doesn't mean anything when the server itself is refusing to talk to you.
What about p2p and less scrupulous actors like TPB? I guess in China the former is probably more effective but this sort of thing is immediately what I thought of when I read OP
The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.
Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.
The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"
Russia's ROSKOMNadzor has been trying to get users to install its own Root CAs in recent years. About 10 years ago everyone in the west removed CNNIC (Chinese counterpart) roots after they were caught MITM-ing.
Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:
1. Make it illegal to distribute a browser that distrusts their CA
2. Make it illegal to run a browser that distrusts their CA
3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software
Sure, a state can do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals harder; they can no longer do as much surreptitiously.
> Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS
I mean... They could, though, no? If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.
> If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.
I'm sure that works in a Hollywood movie, in the same way you could reverse the polarity of the lasers to enable you to travel inside the computer from a household video projector, or decrypt all the world's telephone calls using a device built into your batmobile - but this isn't a Hollywood movie and so traffic isn't in fact "encrypted with a root cert".
If for any of a variety of reasons the Chinese authorities don't want your connection to exist they'll terminate the connection, exactly as I described in my earlier comment.
Yes China will kill your network connections. And that is proof that Internet cannot route around censorship. Any time Internet routes around censorship China finds a new way to censor it.
Normal people don’t care about “downgrade” or “decrypt” or “intercept” they care about availability.
In times of low social unrest theyd rather create a list of dissidents than try to shut them down. Keeps unrest lower and then when they need to spin up the domestic security apparatus they already know who to watch
Until a time of "civil unrest" occurs, and suddenly your "super easy" VPN becomes entirely blocked at the very same moment you wish you had it the most.
They aren't stupid, they're not going to insta-block everything they can detect, giving away clues to people trying to evade it.
> Over the last two years, Iran officials warned that wider use of the satellite internet service could make communication controls within the country "ineffective", adding the regime has failed to produce an adequate policy response.
> “I sometimes joke that we might as well turn the Ministry of Communications and the Supreme Council of Cyberspace into amusement parks, because they will no longer serve any purpose,” Hakami said.
It's certainly less true than it was. It depends on how Matt Prince feels on any particular day.
To a large degree, most of the internet today is ultimately controlled by a few people. If what you have to say pisses off these people, and someone is determined to keep you off the internet, you have a problem. Kiwi Farms is a well known example, and continues to suffer under regular DDOS attacks. Regardless of how you feel about KF, it's undeniable that a) this nonsense has streissanded the site enormously and b) it's speech you don't like that needs protection.
Also there was the whole covid "misinformation" garbage fire... I certainly do not want my government or some megacorp to decide what can and can't say or read.
And going beyond the internet, I just want to remind you Americans, that your 1st amendment is almost unique (to my knowledge). Enjoy and protect your offensive, hateful, blasphemous, extremist, and deeply unpopular speech.
It's true unless we let freedom of speech and the press be interpreted narrowly, as the right to flap our jaws and to press paper against ink. That is up to us collectively.
The internet will always route around censorship in principled western nations.
It's a politico-technological arms race. They make their laws. We make technology that completely nullifies their laws. They need to increase their tyranny in order to enjoy the same level of control they had before. The end state is either a totalitarian government or an uncontrollable population.
I used to think that we'd find some kind of equilibrium along the way, that we'd eventually discover the government's limits: some principle they refuse to break, some line they refuse to cross...
But the truth is these tyrants have no limits whatsoever. They'll stop at nothing in their quest to control the flow of information.
Not sure what the impossibility is. VPN's have a set of exit relays. If traffic is coming from one of those exit relays, it's coming from a VPN, so adult websites can be required to block traffic from those exit relays. What am I missing?
It's impossible to have a full and complete list of VPN exit nodes, for the simple reason that no company publishes the full list, and also technically if you set up an OpenVPN server on digital ocean and connect to that you're also using a VPN but no one would know your address is hosting a VPN server.
Utah could demand the moon, it doesn't mean that the federal government would agree they have a right to that demand.
Utah can't tell businesses that service the country (or the world) how to do anything in this regard. You can't demand a list of the VPN exit nodes, because no VPN would ever give you that, and if they're outside of your jurisdiction, how could you possibly enforce it (assuming you got the Feds to agree with your law regulating interstate/international commerce now). You can't tell websites to only accept residential traffic, for the same reasons.
The internet sorta fucks states rights (in a good way).
You'd have to ask every non-residential host online to do the same. As above, you can get a DigitalOcean droplet and ssh -D to it, now you have a SOCKS proxy that for state's concern is doing the same as a VPN.
Why would a VPN company care about what Utah requires if they have no legal presence there(or in the US for that matter)?
Besides, there's no such thing as "residential" IPs. If I set a VPN gate at my mum's house, how would the porn company know?
The "impossibility" is in them saying "we cannot guarantee with 100% certainty that the user isn't using a VPN" and that's correct, they can't - but the law has no provision for that, they are risking fines over something they cannot control.
I would think that requiring adult websites to essentially block all VPN traffic to be pretty heavy handed and hardly a solution. Especially considering there are many reasons to use a VPN.
The law likely violates the U.S. Constitution’s prohibition on passing laws that significantly burden businesses and people outside Utah’s borders.
SB 73 burdens the rights of all internet users outside of Utah because it requires adult websites to either know every visiting user’s physical location, and then block those in Utah, or to verify every visitor’s age just in case they might be in Utah.
It's technically impossible to both implement Utah's law and respect the constitution. To make it technically feasible you'd need to either change the constitution or federalize the law.
The law is only meant to apply to citizens of Utah though. Blocking all exit relays would mean that absolutely anyone accessing that website would not be able to do so from a VPN which burdens people outside of Utah too.
This is what I was missing. Demanding that porn sites block VPN traffic (or only accept residential traffic) would mean that everyone everywhere using a VPN gets blocked not just in Utah.
I still suspect there's some kind of solution. Like Utah could tell VPN providers that if they service a customer in Utah then the VPN provider can't route traffic to adult sites. Or put the burden on the VPN provider to do age verification if porn is gonna be available through the VPN.
Come to think of it, I'm still a bit confused as to why VPNs are even relevant because it would seem to me that age verification would be done through some kind of having-credit-card type scheme which VPNs are entirely irrelevant to. I even read the article and I'm still confused. Oh well.
You need to understand that my branch considers Catholicism to be a pagan shame and the Mormons an actual sex cult. We just don't talk about our differences anymore because it always ended in death.
The difference is, there are a reasonable number of churches that recognize Catholic or Presbyterian as Christian, even if it's not all of them. Only LDS consider LDS to be Christian.
But don't they still believe in other Christian texts, the same concepts, and the same god in the same way? It's probably more different than most other branches but it still seems like Christian DLC to me.
I think they do in some ways. But they're not generally considered part of the wider Christian church. Perhaps unfairly but I think that's how it's considered.
"It's complicated." I'm not LDS and haven't been a member of the Christian sect I was raised in for many years. I've had besties who were LDS, though, and we talked a lot whenever it came up in conversation. (Which tends to be surprisingly often, FWIW.)
The gist is that LDS members believe that the Bible is true when it has been correctly translated. But that's a gap big enough to drive a truck through. There are some very real irreconcilable differences between the Bible and the Book of Mormon.
For example, Mormons believe in the practice of "sealing"[0], which is basically marriage that lasts for eternity. However, Jesus himself explicitly says in the Bible[1] that this isn't so:
> The same day the Sadducees, who say there is no resurrection, came to Him and asked Him, saying: “Teacher, Moses said that if a man dies, having no children, his brother shall marry his wife and raise up offspring for his brother. Now there were with us seven brothers. The first died after he had married, and having no offspring, left his wife to his brother. Likewise the second also, and the third, even to the seventh. Last of all the woman died also. Therefore, in the resurrection, whose wife of the seven will she be? For they all had her.” Jesus answered and said to them, “You are mistaken, not knowing the Scriptures nor the power of God. For in the resurrection they neither marry nor are given in marriage, but are like angels of God in heaven.
Personally, it seems exceedingly unlikely to me that each one of the translations on the linked page are wrong in exactly the same way.
Anyway, that's why lots of LDS will say that they're Christians. If asked, they believe that the Bible is true where correctly translated, but in my (admittedly) limited experience, not many of them as a percentage have actually read the Bible themselves to know what it actually says about this. It's also why a lot of Christians say that LDS are not: they believe in lots of things that are not in the Bible, and believe that the Bible we have today has lots of mistakes.
NB: I'm not staking an opinion on any of this, or taking sides on the matter. I'm offering this in the same sense that I might share something I learned in history class about the French Revolution. It's interesting to read and learn about, but doesn't directly affect me and it's not anything I want to participate in. Especially do not take this chance to explain to me why the whole "left his wife to his brother" thing is f'ed up by modern standards.
| An individual is considered to be accessing the website from this state if the individual is actually located in the state, regardless of whether the individual is using a virtual private network, proxy server, or other means to disguise or misrepresent the individual's geographic location to make it appear that the individual is accessing a website from a location outside this state.
But how can any site check if a client is a) a VPN client (typically this can be known because VPN exit node IPs can be learned), __and__ b) in Utah?
The impossibility lies in (b). Effectively this forces any affected companies having a nexus to the state of Utah to forbid VPN clients. I think that's a bit too far-reaching. It would be much more practicable instead to ask VPNs to disallow Utah client exits to affected sites w/o age checks -- VPN services aren't free, so VPNs basically can do age checks.
Given that this could have been written to be feasibly implemented, either this text was written to cause a controversy, or this text was written by people who don't know how things work. Either way, this text cannot be enforceable as written. The Utah legislature can easily modify this to be enforceable (see above), so it's not like a court striking this down might be playing partisan games just by striking it down.
The people who wrote it and the people who ratified didn't seem to think it was absolute. The First Amendment was not intended to create a new right of speech. It was intended to prevent the new federal government from abridging the existing right as it was under common law and state law.
Under state and common law at the time many kinds of speech were routinely regulated or even criminalized, such as defamation and blasphemy.
They weren't short on ink. If they wanted to add additional conditions and tweaks, they would have. What they thought, or what they wrote down elsewhere, doesn't matter.
They seem to know what they're doing here. A website can comply as long as they perfectly geofence (impossible) or do "reasonable" age verification. "Reasonable" only for the latter. So they basically want these sites in any US state to do age verification.
What stops me from using DraftKings.com from a VPN? I'm at the page right now, but I don't have an account. Will they verify that my IP and home address match or something?
They have an extensive blacklist of VPNs, and on top of that will require you to verify location on a phone if you don't have an obvious residential IP. Or maybe they just always do that? Of course if you have a sketchy proxy and a phone where you can spoof location and you can ensure they don't flag it as something "unverified" like GrapheneOS, you can get around it, and you'd be in a small minority.
Unfortunately know this because a gambler friend showed me.
I've found that some sites (even like restaurants, for example) have no problem setting up an order when I connect via my VPN (from Linux) - my default browsing setup. But when I go to pay, their payment processor refuses to work properly / fails, so I can't actually transact any $$. Others work just fine WITH VPN on. Sadly, the former is increasing and the latter decreasing, to the point it's getting harder and harder.
Heck, Lowes and BestBuy are pretty unusable in general via VPN already.. (or maybe due to ublock, or privacy badger or eff, etc.. :-)
Oh I see, "An individual is considered to be accessing the website from this state if the individual is actually located in the state regardless of whether the individual is using..." as mentioned in the injunction https://www.courthousenews.com/wp-content/uploads/2026/09/ay... So yeah the law would basically require everywhere to perform age verification, where the law says it only has to be "commercially reasonable."
I'm not in California and DraftKings blocks me connecting with a VPN, so they just don't seem to be distinguishing whether a VPN user is in California (which is the impossible part of this law).
Utah argues that websites can "age assure VPN-using Utahns, [so] any decision by Aylo to instead age-verify all users would be a voluntary business choice, not an effect forced by Utah law" because regulating non-Utah users on non-Utah sites is not something the Utah law can constitutionally do under the Dormant Commerce Clause.
So in theory sites could block all VPN users (if you can somehow "perfectly (1) detect VPN/proxy users"), but if the law necessitates that nationally/globally then it's unconstitutional anyway. It's the age assuring of VPN-users specifically from Utah part that Utah are relying on being possible for the law the be constitutional.
I think "The Church" (The Church of Jesus Christ of Latter-Day Saints) is trying to keep Pornhub from publishing stats of how many ~people~ ~righteous Church members~ Melchizedek Priesthood holders are whacking to "cosplay porn" and "lesbian porn".
If you want to ban ISP's in your state, or build a state firewall, or arrest your citizens, you are welcome to do so - but what happens on servers outside your state that your state is choosing to connect to is clearly none of your business.
Seems like we need a fundamental challenge to the concept that you have any jurisdiction whatsoever.
Being able to tie an IP to a rough physical location was, in retrospect, a huge Internet design mistake. IPs should be like random UUIDs. They should have been designed to get assigned randomly when you obtain one, rotated / thrown away periodically, with no hierarchical numeric relationship with the ISP that is assigning them.
It was much easier to assign blocks of IPs to an ISP rather than a 4.3B line lookup table. And how would you ensure that an address has been rotated? How do you determine who the real owner of an IP is when collisions occur? You're asking for a worldwide atomic database propagated to all routers in the days where a 32bit number was considered massive.
Fascism is on the march. Dirty pictures aren't the real reason governments want this level of control over the internet. You can be sure that we'll see worse. Glad we won this battle.
Can someone explain why it wouldn't work to have porn companies use only certain domains, and filter based on those domains, if people are so intent on blocking it?
Because you shouldn't get behind a thing that shouldn't exists. Technical solutions to societal problems are and will always be naught and fraught with unnecessary jump roping. In this case, the content itself isn't dangerous, what is dangerous is consuming it without the correct context, ie. education.
The smart version of this is that adult content providers send a header or something with every response that contains NSFW, and then you use parental controls on client devices to not show those responses. This even works for sites that show a mix of kid-friendly and adult content cough reddit cough. It offers fewer opportunities for general purpose censorship, though, so there's less interest.
The US Congress evaluated [1] the legality of forcing adult websites onto certain TLDs in the 2000s and it was determined to be legally ambiguous and would almost certainly face substantial 1st amendment challenges. So they didn't pursue it.
JSR_FDED | 5 hours ago
roughly | 4 hours ago
Doesn't help your arm, but when they're asking for things in that second category, it doesn't help them either.
cwillu | 4 hours ago
not_a_bot_4sho | 4 hours ago
roughly | 4 hours ago
recursive | 4 hours ago
m463 | 3 hours ago
thayne | 3 hours ago
howunfortunate | 2 hours ago
pseudosavant | 2 hours ago
cheesecakegood | an hour ago
SoftTalker | 4 hours ago
Is it even possible to reliably know that a connection is from a VPN? Anyone can proxy through a random hosting provider.
ad_fontes | 4 hours ago
ranger_danger | 4 hours ago
codedokode | 4 hours ago
iAMkenough | 4 hours ago
codedokode | 3 hours ago
iAMkenough | 2 hours ago
Under Utah's law as written, a private business has to assume any single IP address could be operating a VPN/proxy.
malfist | 4 hours ago
Since when do you have to pull permits to put a server on the web?
ranger_danger | 4 hours ago
zen928 | 3 hours ago
irenaeus | 4 hours ago
The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.
Rohansi | 3 hours ago
So if you are legally required to block all VPN users and then fail to actually block all VPN users what is stopping you from being punished for not complying with the law?
mahboi | 3 hours ago
fc417fc802 | 57 minutes ago
EvanAnderson | 3 hours ago
To handle the matter technically Utah would need a "great firewall of Utah" and a legislative mandate that all ISPs route thru it. Somehow they'd have to factor-in signals from cellular sites neighboring states and satellites.
not_a_bot_4sho | 4 hours ago
I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)
I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying
alnwlsn | 4 hours ago
manquer | 4 hours ago
There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.
The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).
Netflix are/were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.
[1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.
kevincox | 3 hours ago
buckle8017 | 3 hours ago
Aurornis | 4 hours ago
The simplest methods block known datacenter IP ranges like you thought. More will score it based on several heuristics and a reputation over time. If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.
a4isms | 3 hours ago
Or, their so-called "smart" TV is acting as a proxy without their informed consent.
codedokode | 4 hours ago
llama052 | 4 hours ago
Let’s block traffic on the internet blindly just in case someone is looking at an adult website.
hn_acc1 | 3 hours ago
fc417fc802 | an hour ago
TeMPOraL | 4 hours ago
irenaeus | 4 hours ago
michaelbuckbee | 3 hours ago
mahboi | 3 hours ago
SV_BubbleTime | 2 hours ago
It’s starting to get annoying that things aren’t working. They’re shooting themselves in the foot though.
If they didn’t block VPNs, they would at least know what category to group them in.
happyPersonR | 3 hours ago
Folks would just host their own vpns various places and this would be pointless ….
unglaublich | 3 hours ago
pkilgore | 2 hours ago
pessimizer | 2 hours ago
EA-3167 | 2 hours ago
The government demonstrably has the ability to break into your comms and data without going through any of this. Instead of a libertarian conspiracy theory have you considered that politicians chase power and re-election?
Taking a stand and making major changes is hard to pull off, costs a lot of political resources, and can backfire horribly. Doing symbolic, popular crap that’s popular with the (admittedly thick and ignorant) majority is an easy win. Moral outrage is an easy win. “Think of the children” is an easy win.
Ed: Corrected “comma” to “comms”
HeatrayEnjoyer | 2 hours ago
0cf8612b2e1e | 2 hours ago
bigbuppo | 2 hours ago
/Same as it ever was
pimeys | 2 hours ago
lokar | an hour ago
- religious/cultural. My beliefs forbid this, it makes people bad/worse in some hard-to-define way, so no one should be allowed to do it. Sometimes with an emphasis that the sellers are luring good people into sin/ruin.
- it harms women. Many of the participants are trafficked or coerced in some way (and further abused). The profits from the industry encourage more of this. It “warps” the mind of men who use it, leading them to mistreat and abuse women.
I see elements of truth in all these, but IMO they are ultimately not compelling, prohibition is unworkable and unduly infringes on willing participants and consumers.
throwinthisaway | an hour ago
I’ve watched plenty of porn in my life, probably a bit more than average. I’ve never done anything out of the norm or unwanted to woman, let alone abuse one.
I think shitty people will be shitty people and it’s just a really easy thing to point at instead of taking responsibility for it. It’s also a convenient plausible sounding correlation for people who already want to ban porn to use.
schrodinger | an hour ago
Umm, I played plenty of GTA growing up and I’ve never stolen a car. People are actually very good at separating fantasy from reality, believe it or not.
lokar | an hour ago
BobaFloutist | 19 minutes ago
UltraSane | 37 minutes ago
lokar | 30 minutes ago
jonahx | 4 minutes ago
I am all for individual freedoms, but I've read enough about this issue, and seen enough documentaries, that I think the claim is very well-founded. Of course, some porn stars are just willing adults who doing something they want to do, but there are many who are not.
GolfPopper | 46 minutes ago
That's one reason why traditionists in power usually crack down on any sort of pornography or alternate sexuality. Sex is a huge driver for human behavior. And established power structures would prefer that the only way for anyone to get sex is via compliance with the existing power structures. It's not something where the establishment is ever going to be able to perfectly control things, but if they can make it more difficult to get any sort of sexual gratification that doesn't align with their preferred social structure that gives the establishment an advantage in holding on to power.
miohtama | 44 minutes ago
Ofcom is investigating PornHub even after PornHub installed age checks as Ofcom claims age checks not “robust” (read: VPN ban). So hand over your id to see porn.
https://x.com/moo9000/status/2102726344975040565?s=20
sparkling | 2 hours ago
Now of course, if your VPN is a home-lab style VPN where you are connecting to a little wireguard box sitting in your own home, that is a totally different story.
compiler-guy | 2 hours ago
mmooss | 2 hours ago
In the real world, very few people have that capability.
mey | 2 hours ago
Less savvy individuals/business would also have no reason to obey these laws.
See https://en.wikipedia.org/wiki/Evil_bit
mmooss | an hour ago
The limitation is technical skill, even having enough skill to know that this is a solution.
campbel | an hour ago
stingraycharles | 13 minutes ago
gorgoiler | 2 hours ago
babelfish | 2 hours ago
gwbas1c | 2 hours ago
There is a very vocal anti-porn group in Utah. They do things like put up massive billboards that say "[Store name] sells porn." (Which is basically free advertising instead of shaming.)
semiquaver | 2 hours ago
greyface- | 2 hours ago
eptcyka | an hour ago
On the other hand, using Masque for TCP transfers will probably fool a server to believe the MSS is 1500.
LoganDark | an hour ago
No, it's not possible. You can only try to identify known protocols or suspicious patterns of data, timing or entropy. Theoretically, with a big enough collaboration, you could hide a VPN behind shaping traffic patterns and request order towards hundreds of different servers, and there's just no method of traffic analysis that can possibly identify that without prior knowledge.
Like, some firewalls try to identify an absence of connections outside the VPN, or an abnormal volume of data over a sustained period of time. But all that goes out the window when, say, you are connecting to hundreds of real servers at all times and only exchanging, say, basic HTTP requests with each one. For all they know you just have a million browser toolbars installed. They wouldn't know if the choice of request, order and timing encodes information because they wouldn't be able to prove what the client's intentions are in sending it or what the servers do with it.
If you tried to identify it, you would block every real connection.
I believe some VPN providers are beginning to play with things like this, but the problem is really that it's impossible to provide this. It only really works when you run it yourself, because that's the only way others don't know. So they're having to settle for compromises, like Mullvad's DAITA, which still uses a single server but tries to avoid showing tells of a VPN connection as opposed to something else like streaming.
usernomdeguerre | 4 hours ago
Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.
Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.
Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.
TJSomething | 4 hours ago
iAMkenough | 4 hours ago
A VPN/proxy could exist at almost any single address at any given time.
jason1cho | 4 hours ago
nemomarx | 4 hours ago
So there is a route around censorship, but maybe the public doesn't really care about it.
Scaled | 4 hours ago
jason1cho | 4 hours ago
hnav | 3 hours ago
snohobro | 4 hours ago
I suppose Utah could impose some sort of strategy here, but would be so burdensome and anti-American I’m not sure they could pull it off. Instead of a blacklist of sites dictated by the site provider, you go the other way where all Utah ISPs maintain a whitelist of IPs permitted to Utah citizens. Any traffic attempting to reach a non-white listed IP, would be rejected.
hn_acc1 | 3 hours ago
TeMPOraL | 4 hours ago
The layer 2 and 3 of ISO/OSI stack does indeed "route around censorship". But the Internet as we know it is all Layer 7, and it's as centralized as it gets.
That's why regulators often aim straight at Layer 7 entities - companies providing consumer services over the web. Because no matter how unblockable the route between you and some server is, it doesn't mean anything when the server itself is refusing to talk to you.
mxkopy | 4 hours ago
EvanAnderson | 3 hours ago
tialaramex | 4 hours ago
Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.
The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"
nazcan | 3 hours ago
hnav | 3 hours ago
JoshTriplett | 3 hours ago
ndriscoll | 2 hours ago
JoshTriplett | 2 hours ago
tenacious_tuna | 3 hours ago
I mean... They could, though, no? If they control the gateways they could drop any traffic that isn't encrypted with some root cert that allows them to decrypt in transit packets.
tialaramex | 2 hours ago
I'm sure that works in a Hollywood movie, in the same way you could reverse the polarity of the lasers to enable you to travel inside the computer from a household video projector, or decrypt all the world's telephone calls using a device built into your batmobile - but this isn't a Hollywood movie and so traffic isn't in fact "encrypted with a root cert".
If for any of a variety of reasons the Chinese authorities don't want your connection to exist they'll terminate the connection, exactly as I described in my earlier comment.
kccqzy | 3 hours ago
Normal people don’t care about “downgrade” or “decrypt” or “intercept” they care about availability.
anamexis | an hour ago
HDThoreaun | an hour ago
Terr_ | 25 minutes ago
They aren't stupid, they're not going to insta-block everything they can detect, giving away clues to people trying to evade it.
simlevesque | 3 hours ago
> “I sometimes joke that we might as well turn the Ministry of Communications and the Supreme Council of Cyberspace into amusement parks, because they will no longer serve any purpose,” Hakami said.
https://gulfnews.com/world/mena/iran-official-says-starlink-...
encom | 3 hours ago
To a large degree, most of the internet today is ultimately controlled by a few people. If what you have to say pisses off these people, and someone is determined to keep you off the internet, you have a problem. Kiwi Farms is a well known example, and continues to suffer under regular DDOS attacks. Regardless of how you feel about KF, it's undeniable that a) this nonsense has streissanded the site enormously and b) it's speech you don't like that needs protection.
Also there was the whole covid "misinformation" garbage fire... I certainly do not want my government or some megacorp to decide what can and can't say or read.
And going beyond the internet, I just want to remind you Americans, that your 1st amendment is almost unique (to my knowledge). Enjoy and protect your offensive, hateful, blasphemous, extremist, and deeply unpopular speech.
abecedarius | 3 hours ago
mahboi | 3 hours ago
matheusmoreira | 2 hours ago
It's a politico-technological arms race. They make their laws. We make technology that completely nullifies their laws. They need to increase their tyranny in order to enjoy the same level of control they had before. The end state is either a totalitarian government or an uncontrollable population.
I used to think that we'd find some kind of equilibrium along the way, that we'd eventually discover the government's limits: some principle they refuse to break, some line they refuse to cross...
But the truth is these tyrants have no limits whatsoever. They'll stop at nothing in their quest to control the flow of information.
irenaeus | 4 hours ago
gambiting | 4 hours ago
irenaeus | 4 hours ago
It also seems to me like Utah could just demand that adult sites only accept traffic from residential ips.
moate | 4 hours ago
Utah can't tell businesses that service the country (or the world) how to do anything in this regard. You can't demand a list of the VPN exit nodes, because no VPN would ever give you that, and if they're outside of your jurisdiction, how could you possibly enforce it (assuming you got the Feds to agree with your law regulating interstate/international commerce now). You can't tell websites to only accept residential traffic, for the same reasons.
The internet sorta fucks states rights (in a good way).
techjamie | 3 hours ago
gambiting | 3 hours ago
Besides, there's no such thing as "residential" IPs. If I set a VPN gate at my mum's house, how would the porn company know?
The "impossibility" is in them saying "we cannot guarantee with 100% certainty that the user isn't using a VPN" and that's correct, they can't - but the law has no provision for that, they are risking fines over something they cannot control.
llama052 | 4 hours ago
gchamonlive | 4 hours ago
Dfiesl | 4 hours ago
irenaeus | 59 minutes ago
I still suspect there's some kind of solution. Like Utah could tell VPN providers that if they service a customer in Utah then the VPN provider can't route traffic to adult sites. Or put the burden on the VPN provider to do age verification if porn is gonna be available through the VPN.
Come to think of it, I'm still a bit confused as to why VPNs are even relevant because it would seem to me that age verification would be done through some kind of having-credit-card type scheme which VPNs are entirely irrelevant to. I even read the article and I'm still confused. Oh well.
Aurornis | 4 hours ago
It's impossible to have perfect knowledge of the entire set of VPN exit node addresses.
nikanj | 4 hours ago
logicchains | 3 hours ago
neilo40 | 3 hours ago
mahboi | 3 hours ago
gopher_space | 3 hours ago
You need to understand that my branch considers Catholicism to be a pagan shame and the Mormons an actual sex cult. We just don't talk about our differences anymore because it always ended in death.
onraglanroad | 3 hours ago
It's like I thought the Gospel Church in Northern Ireland would have better music. Turns out not.
gopher_space | 2 hours ago
onraglanroad | 2 hours ago
gopher_space | an hour ago
The bit starts at 2:00
If you're ever in San Francisco, Grace Cathedral is worth a visit.
mahboi | 43 minutes ago
onraglanroad | 3 hours ago
tavavex | 2 hours ago
onraglanroad | 2 hours ago
mahboi | 41 minutes ago
kstrauser | 6 minutes ago
The gist is that LDS members believe that the Bible is true when it has been correctly translated. But that's a gap big enough to drive a truck through. There are some very real irreconcilable differences between the Bible and the Book of Mormon.
For example, Mormons believe in the practice of "sealing"[0], which is basically marriage that lasts for eternity. However, Jesus himself explicitly says in the Bible[1] that this isn't so:
> The same day the Sadducees, who say there is no resurrection, came to Him and asked Him, saying: “Teacher, Moses said that if a man dies, having no children, his brother shall marry his wife and raise up offspring for his brother. Now there were with us seven brothers. The first died after he had married, and having no offspring, left his wife to his brother. Likewise the second also, and the third, even to the seventh. Last of all the woman died also. Therefore, in the resurrection, whose wife of the seven will she be? For they all had her.” Jesus answered and said to them, “You are mistaken, not knowing the Scriptures nor the power of God. For in the resurrection they neither marry nor are given in marriage, but are like angels of God in heaven.
Personally, it seems exceedingly unlikely to me that each one of the translations on the linked page are wrong in exactly the same way.
Anyway, that's why lots of LDS will say that they're Christians. If asked, they believe that the Bible is true where correctly translated, but in my (admittedly) limited experience, not many of them as a percentage have actually read the Bible themselves to know what it actually says about this. It's also why a lot of Christians say that LDS are not: they believe in lots of things that are not in the Bible, and believe that the Bible we have today has lots of mistakes.
[0]https://en.wikipedia.org/wiki/Sealing_(Mormonism)
[1]https://www.bible.com/bible/compare/MAT.22.23-30
NB: I'm not staking an opinion on any of this, or taking sides on the matter. I'm offering this in the same sense that I might share something I learned in history class about the French Revolution. It's interesting to read and learn about, but doesn't directly affect me and it's not anything I want to participate in. Especially do not take this chance to explain to me why the whole "left his wife to his brother" thing is f'ed up by modern standards.
pchristensen | 3 hours ago
cryptonector | 2 hours ago
| An individual is considered to be accessing the website from this state if the individual is actually located in the state, regardless of whether the individual is using a virtual private network, proxy server, or other means to disguise or misrepresent the individual's geographic location to make it appear that the individual is accessing a website from a location outside this state.
But how can any site check if a client is a) a VPN client (typically this can be known because VPN exit node IPs can be learned), __and__ b) in Utah?
The impossibility lies in (b). Effectively this forces any affected companies having a nexus to the state of Utah to forbid VPN clients. I think that's a bit too far-reaching. It would be much more practicable instead to ask VPNs to disallow Utah client exits to affected sites w/o age checks -- VPN services aren't free, so VPNs basically can do age checks.
Given that this could have been written to be feasibly implemented, either this text was written to cause a controversy, or this text was written by people who don't know how things work. Either way, this text cannot be enforceable as written. The Utah legislature can easily modify this to be enforceable (see above), so it's not like a court striking this down might be playing partisan games just by striking it down.
nikanj | 4 hours ago
rhcom2 | 4 hours ago
How is that not a blatant first amendment violation?
criddell | 3 hours ago
CamperBob2 | 2 hours ago
tzs | an hour ago
Under state and common law at the time many kinds of speech were routinely regulated or even criminalized, such as defamation and blasphemy.
CamperBob2 | an hour ago
Or at least it shouldn't.
rhcom2 | 2 hours ago
MBCook | 2 hours ago
calvinmorrison | 4 hours ago
ceroxylon | 3 hours ago
mahboi | 2 hours ago
stonogo | 2 hours ago
mahboi | 3 hours ago
abirch | 3 hours ago
mahboi | 3 hours ago
abirch | 3 hours ago
mahboi | 3 hours ago
Unfortunately know this because a gambler friend showed me.
hn_acc1 | 3 hours ago
Heck, Lowes and BestBuy are pretty unusable in general via VPN already.. (or maybe due to ublock, or privacy badger or eff, etc.. :-)
compiler-guy | 3 hours ago
This Utah law requires perfection.
mahboi | 3 hours ago
Ukv | 3 hours ago
mahboi | 3 hours ago
iAMkenough | 3 hours ago
A VPN/proxy could exist on any given IP address at any time, which the California law recognizes but the Utah law does not.
Ukv | an hour ago
So in theory sites could block all VPN users (if you can somehow "perfectly (1) detect VPN/proxy users"), but if the law necessitates that nationally/globally then it's unconstitutional anyway. It's the age assuring of VPN-users specifically from Utah part that Utah are relying on being possible for the law the be constitutional.
knicholes | 3 hours ago
Henchman21 | 2 hours ago
bnteke | 2 hours ago
stefangordon | 3 hours ago
Seems like we need a fundamental challenge to the concept that you have any jurisdiction whatsoever.
ryandrake | 3 hours ago
wildzzz | 2 hours ago
kramer2718 | 3 hours ago
forshaper | 2 hours ago
braiamp | 2 hours ago
bell-cot | 2 hours ago
kstrauser | 24 minutes ago
andrewflnr | an hour ago
petcat | 54 minutes ago
https://www.everycrsreport.com/files/20080714_RL33224_1e6b93...
nadermx | an hour ago
1vuio0pswjnm7 | an hour ago
It won't route around self-censorship that arises out of surveillance
Nor will it take a stand against SNI which is a dead simple means of implementing censorship that's in widespread use every day for years
newsclues | 48 minutes ago