⏱️ Reading time: 13 min

A federal court in Utah just confirmed something every network engineer has known for years: there is no reliable age verification when the visitor uses a VPN. Judge Barlow blocked enforcement in September 2026 of SB73, the law that required adult sites to geolocate every user with perfect accuracy or block anyone who appeared to be hiding their location.

📑 En este artículo
  1. TL;DR
  2. What is a VPN?
  3. The Utah ruling: when the law demands the impossible
  4. Why age verification doesn’t work with an encrypted tunnel
  5. Practical examples: seeing encryption (and opacity) in action
  6. Getting started: test it on your own machine
  7. Why IP geolocation is never perfect
  8. Real-world VPN uses beyond dodging a block
  9. Comparison: which age-verification methods a VPN dodges
  10. Common misconceptions about VPNs and age checks
  11. Going deeper: the leaks that can actually give you away
  12. Frequently Asked Questions
    1. Can a VPN dodge any age verification system?
    2. Why does a VPN prevent accurate identity verification?
    3. Does SB73 ban using a VPN in Utah?
    4. Does a VPN make me completely anonymous to every site?
    5. How does WireGuard differ from a traditional VPN like OpenVPN?
  13. References

The court order does not address whether the law is a good idea. It addresses whether it’s possible to comply with it, and the technical answer is no: a VPN encrypts traffic and replaces the user’s real IP with that of the intermediary server, so no site can know with certainty where a connection actually comes from.

TL;DR

  • A VPN encrypts traffic up to its server: the destination site only sees that server’s IP, never the real user’s.
  • Judge Barlow blocked Utah’s SB73 in September 2026 because it requires a level of geolocation the network can’t guarantee.
  • WireGuard encrypts every packet with ChaCha20-Poly1305 before it leaves the device: neither the ISP nor the site can read the content.
  • A tcpdump on a VPN interface shows no GET line at all, where the plaintext HTTP request used to be readable.
  • ID-document age checks do work over a VPN because they don’t depend on the IP.

What is a VPN?

A VPN is an encrypted tunnel that routes a device’s traffic through an intermediary server before it reaches the internet, so the destination only sees that server’s IP, and no IP-based age verification system can confirm who’s actually behind it.

There are several families of VPN protocols, each with different trade-offs between speed, security, and compatibility. WireGuard uses modern cryptography (Curve25519, ChaCha20-Poly1305) in a minimalist design of just a few thousand lines of code. OpenVPN is older, runs over TLS, and supports more configurations, but is heavier computationally. IPsec is used mainly in corporate networks and home routers.

What they all share is the same design principle: data leaves the user’s device encrypted and is only decrypted at the VPN server, which then forwards it to the final destination using its own source IP. To the website, the connection appears to come from that server regardless of which country the user is actually in.

The Utah ruling: when the law demands the impossible

SB73 was signed in early 2026 and was set to take effect that May. The law required adult sites to block any visitor who appeared to be using a VPN or other traffic-hiding tool, or else verify the age of all their users in case any of them were physically in Utah. The statute even barred those sites from explaining how to use a VPN to bypass the check, though that part of the law wasn’t challenged in this particular lawsuit.

Aylo, Pornhub’s parent company, sued the state. Its central argument: the law doesn’t distinguish between monitoring Utah users and monitoring the 28 million users Aylo has across the United States, because any of them could be using a VPN without the site knowing for sure.

💭 Key point: Judge Barlow didn’t rule on whether blocking VPNs is desirable. He ruled on whether perfect geolocation is technically possible, and concluded it isn’t, which completely changes the legal analysis of the burden on interstate commerce.

The law’s compliance rules (known as R152-78B) were published on September 1, 2026, and were set to take effect on October 8 that same year, but the judge’s preliminary injunction suspends them while the litigation proceeds.

SB73’s compliance rules were set to take effect on October 8, 2026, before the court blocked them. Foto de Zulfugar Karimov en Unsplash

Why age verification doesn’t work with an encrypted tunnel

The problem isn’t that VPNs are hard to detect. The problem is that even if a site manages to detect one, that reveals nothing useful about the age or real identity of whoever is behind it.

When a website receives a connection, it only sees three things: the source IP address, the packet metadata (size, timing, port), and, if there’s no encryption, the content. A VPN intervenes on all three fronts at once. It replaces the visible IP, homogenizes much of the traffic pattern, and encrypts the content end-to-end between the device and the VPN server.

flowchart TD
A["Original plaintext data"] --> B["Encrypted with WireGuard (ChaCha20-Poly1305)"]
B --> C["Encapsulated in a UDP packet"]
C --> D["Leaves through the device's network interface"]
D --> E["Passes through the ISP with content unreadable"]
E --> F["Reaches the VPN server, which decrypts it"]
F --> G["The VPN server forwards the request to the destination site"]

IP geolocation databases like MaxMind or IP2Location assign address ranges to countries based on who administratively registered that block, not on where each packet is physically located at a given moment. A VPN server with an IP registered in Amsterdam still shows up as Dutch regardless of whether the real user is in Salt Lake City or Bogotá.

sequenceDiagram
participant U as User
participant I as ISP
participant V as VPN Server
participant S as Website
U->>I: packet encrypted by WireGuard
I->>V: forwards unreadable bytes
V->>S: requests the page with its own IP
S-->>V: responds with the content
V-->>U: forwards the decrypted response
Note over I,S: the ISP and the site never jointly see the user's real IP

Practical examples: seeing encryption (and opacity) in action

The difference between plaintext and encrypted traffic can be observed directly with a packet capture tool. neverssl.com is a real site designed to serve unencrypted HTTP, built exactly for this kind of test.

sudo tcpdump -i eth0 -A -s0 -c 1 'tcp port 80 and host neverssl.com'

This command captures one packet from the direct connection (no VPN) and shows its content in ASCII. The output includes the full HTTP request, readable in plain text:

GET / HTTP/1.1
Host: neverssl.com
User-Agent: curl/8.5.0
Accept: */*

Now, with the same command pointed at the interface of an active WireGuard tunnel, the request no longer shows up anywhere. Instead of eyeballing the content, the most reliable approach is to filter for the string that would identify an unencrypted HTTP request:

sudo tcpdump -i wg0 -c 20 -A | grep -i "GET "

On the direct interface, that command returns the line GET / HTTP/1.1 almost immediately. On the wg0 interface with the tunnel active, it returns no line at all, because the captured bytes are the output of ChaCha20-Poly1305 and contain no recognizable text anywhere in the packet.

You can also confirm the public IP change with curl ifconfig.me. Before bringing up the tunnel, the command returns the real IP assigned by the ISP (for example, an address from the 203.0.113.0/24 range, reserved by the IETF for documentation examples). After bringing up the tunnel, it returns the VPN server’s IP, with no real geographic relationship to the user.

Getting started: test it on your own machine

To reproduce these tests on Linux (Debian or Ubuntu), you only need the wireguard-tools package and superuser permissions. On macOS the equivalent is brew install wireguard-tools, and on Windows it’s enough to install the official client from the WireGuard site.

sudo apt update && sudo apt install -y wireguard

The next step is generating a key pair with the command documented in WireGuard’s official quick start guide:

wg genkey | tee privatekey | wg pubkey > publickey

With that key pair and a .conf file (the one provided by any VPN provider’s dashboard that uses WireGuard, or one put together following the official guide for a self-hosted server), you bring up the interface:

sudo wg-quick up wg0

The typical output shows the network commands that wg-quick runs internally, something like:

[#] ip link add wg0 type wireguard
[#] wg setconf wg0 /dev/fd/63
[#] ip -4 address add 10.x.x.x/32 dev wg0
[#] ip link set mtu 1420 up dev wg0

From there, repeating curl ifconfig.me and the tcpdump filter for GET from the previous section reveals the IP change and the disappearance of plaintext. To close the tunnel: sudo wg-quick down wg0.

WireGuard encrypts with Curve25519 and ChaCha20-Poly1305 in a design of just a few thousand lines.

Why IP geolocation is never perfect

VPN providers constantly add and rotate servers, so no blacklist of known IPs stays accurate for long. An IP that belongs to a VPN server today might be free tomorrow, or reassigned to a different residential provider.

flowchart TD
A["Website receives a connection"] --> B["Queries an IP geolocation database"]
B --> C{"Is the IP on a known VPN list?"}
C -->|"Yes, it's on the blacklist"| D["Blocks the connection"]
C -->|"No, it's a new or residential IP"| E["Lets it through as if local"]
D --> F["New VPN IPs keep appearing constantly"]
E --> F

That asymmetry is exactly what the Utah court recognized as a structural problem, not an accidental one. A site that decides to aggressively block every suspicious IP ends up blocking legitimate users too (for example, employees connecting through a corporate VPN), while a user genuinely intent on evading the check finds a new IP with little effort.

Real-world VPN uses beyond dodging a block

Most VPN traffic in the world has nothing to do with adult sites. Companies use VPNs so remote employees can access internal systems as if they were in the office. Travelers use them to keep notoriously insecure public wifi networks from intercepting their traffic. In countries with active state censorship, a VPN is sometimes the only way to access independent press or basic communication services.

SB73, in fact, doesn’t ban using a VPN itself: it bans an adult site from explaining how to use one to bypass age verification, a separate restriction that Aylo didn’t challenge in this lawsuit. The part the court blocked is the one requiring sites to achieve perfect geolocation, not the one regulating what they can publish about VPNs.

Comparison: which age-verification methods a VPN dodges

This table summarizes which age-verification methods depend on the IP (and therefore fail with a VPN) and which depend on a different kind of data.

MethodWhat it checksDoes a VPN dodge it?Limitation
IP geolocationApproximate device locationYes, alwaysCan’t distinguish VPN traffic from direct traffic
ID documentDeclared real identityNoExposes sensitive data if the site’s database leaks
Credit cardPresumed legal ageNoConfirms access to credit, not real identity
Device attestationHardware and OS configurationPartiallyDepends on the manufacturer and can be bypassed with root or jailbreak
Facial recognitionAge estimated from an imageNot directlyLimited accuracy and requires submitting a photo of the face

Common misconceptions about VPNs and age checks

  • A VPN makes me completely anonymous: the VPN provider does see the user’s real IP and, depending on its logging policy, may store it.
  • All VPNs encrypt the same way: WireGuard, OpenVPN, and IPsec use different primitives and designs, with different trade-offs in speed and attack surface.
  • Blocking known VPN IPs is enough: lists go stale fast because providers constantly rotate servers.
  • Tor is the same as a VPN: Tor routes traffic through at least three nodes run by different volunteers; a VPN depends on a single centralized provider.

Going deeper: the leaks that can actually give you away

An active VPN is no absolute guarantee of opacity. A DNS leak happens when the operating system keeps resolving domain names through the ISP’s DNS servers instead of the tunnel’s, which leaves a record of which sites the user visits even with the main traffic encrypted.

WebRTC, the technology behind in-browser video calls, can reveal the device’s real IP through STUN requests that some browsers send outside the VPN tunnel by default. Neither leak breaks the encryption: they simply let traffic bypass the tunnel.

⚠️ Heads up: a DNS or WebRTC leak can expose the real IP even with an active, well-configured VPN. Checking for this requires dedicated leak-test tools; it’s not enough to just look at the IP a random site shows you.

Even without leaks, a site determined to identify a visitor can resort to device fingerprinting (a combination of screen resolution, installed fonts, system time zone) instead of the IP. That isn’t identity verification in the legal sense SB73 required: it’s a different technique, with its own margin of error, and it wasn’t at issue in the Utah ruling.

Your next step: install wireguard-tools, bring up a test tunnel, and run sudo tcpdump -i wg0 -c 20 -A | grep -i "GET " before and after activating it to see the difference between plaintext and encrypted traffic with your own eyes.

📬 Get new articles by email

We only email about big articles (1-2 a month).

Frequently Asked Questions

Can a VPN dodge any age verification system?

It can dodge any system that depends solely on the source IP, because it replaces that IP with the VPN server’s. It can’t dodge methods that don’t depend on the IP, such as uploading an ID document.

Why does a VPN prevent accurate identity verification?

Because it encrypts traffic content and hides the real IP, the only two pieces of data a site receives by default from each visitor. Without that data, there’s nothing to verify identity or location against.

Does SB73 ban using a VPN in Utah?

Not directly: the part the court blocked requires adult sites to geolocate every visitor with perfect accuracy. The ban on explaining how to use a VPN to bypass the check remains in effect and wasn’t part of this lawsuit.

Does a VPN make me completely anonymous to every site?

No. The VPN provider knows the user’s real IP, and DNS or WebRTC leaks can expose it anyway if the client isn’t properly configured.

How does WireGuard differ from a traditional VPN like OpenVPN?

WireGuard uses a fixed, modern set of cryptographic primitives (Curve25519, ChaCha20-Poly1305) in a codebase much smaller than OpenVPN, which runs over TLS and supports more configuration options at the cost of greater complexity.

References

  • Electronic Frontier Foundation: coverage of the ruling against Utah’s SB73 and the technical argument on the impossibility of perfect geolocation.
  • WireGuard: official documentation of the protocol and its cryptographic primitives.
  • WireGuard Quick Start: official guide for installation and key generation.
  • Wikipedia: general article on virtual private networks.
  • RFC 5737 (IETF): IPv4 address blocks reserved for documentation and examples.

📱 Enjoy this content? Follow @programacion on Telegram for daily tech content in Spanish: quick summaries, fresh content every day.

Featured image: Foto de FlyD en Unsplash

Did it work for you? Got a different error? Say so below: questions get answered and help the next reader.

Leave a comment
Categories: NetworkingTutorials

Javier Alarcón

Infrastructure engineer specializing in networking, Linux systems, Kubernetes, and cloud architectures. Covers hardware, networking, observability, and engineering practices for production teams.

0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *

You can include code inside <code>…</code> or, for several lines, <pre><code>…</code></pre>.

This site uses Akismet to reduce spam. Learn how your comment data is processed.