← Back to context

Comment by cryptonector

4 hours ago

https://le.utah.gov/~2026/bills/static/SB0073.html

| An individual is considered to be accessing the website from this state if the individual is actually located in the state, regardless of whether the individual is using a virtual private network, proxy server, or other means to disguise or misrepresent the individual's geographic location to make it appear that the individual is accessing a website from a location outside this state.

But how can any site check if a client is a) a VPN client (typically this can be known because VPN exit node IPs can be learned), __and__ b) in Utah?

The impossibility lies in (b). Effectively this forces any affected companies having a nexus to the state of Utah to forbid VPN clients. I think that's a bit too far-reaching. It would be much more practicable instead to ask VPNs to disallow Utah client exits to affected sites w/o age checks -- VPN services aren't free, so VPNs basically can do age checks.

Given that this could have been written to be feasibly implemented, either this text was written to cause a controversy, or this text was written by people who don't know how things work. Either way, this text cannot be enforceable as written. The Utah legislature can easily modify this to be enforceable (see above), so it's not like a court striking this down might be playing partisan games just by striking it down.