A federal judge has issued a preliminary injunction blocking enforcement of Utah's SB 73, a law that attempted to force adult websites to detect and block VPN users or determine the precise physical location of every visitor using privacy tools. The ruling lands a clean blow against the growing trend of state legislatures passing internet regulations that are technically impossible to comply with. The court's reasoning is straightforward: the law demands perfect geolocation, and perfect geolocation does not exist. SB 73, signed earlier this year, was the first state law in the U.S. to specifically target VPN usage in the context of age verification. It required adult websites to either identify the exact physical location of every user — including those masking their traffic through VPNs — or verify the age of every visitor globally. It even prohibited covered websites from sharing instructions on how to use a VPN to bypass these checks. The law effectively imposed strict liability: if even one Utah minor accessed a site through a VPN, the platform was on the hook. The constitutional problem is extraterritoriality. Judge Barlow ruled that SB 73 likely violates the dormant Commerce Clause because it forces compliance from every internet user worldwide, not just those in Utah. Adult platforms like Pornhub (owned by Aylo, the plaintiff) serve roughly 28 million users. Under SB 73, all 28 million would need age verification — whether they're in Salt Lake City, Boston, or Honolulu — because the platform cannot reliably distinguish Utah users from anyone else when a VPN is in play. Utah tried to regulate the global internet from a single state capitol. The Electronic Frontier Foundation submitted formal comments to the Utah Department of Commerce detailing the technical impossibility at the law's core. VPNs route traffic through intermediary servers, meaning destination websites see only the VPN server's IP address, not the user's actual location. The state's proposed compliance rules (R152-78B) suggested detection heuristics like monitoring connection latency or device time zones — methods EFF described as notoriously unreliable and easily skewed by normal network conditions. The proposed rules could have taken effect as early as October 8, 2026, but the injunction now blocks enforcement pending further court action. The deeper irony is structural. SB 73 was ostensibly designed to protect minors by enforcing age verification. But to comply with the VPN detection requirement, platforms would need to deploy invasive surveillance of all users' network activity — collecting the very data that privacy tools are designed to protect. The law's response to users avoiding data collection was to mandate even greater data collection. This is compliance theater dressed as child safety, and it would have degraded security for every user, not just those in Utah. Aylo's challenge notably did not contest the provision prohibiting websites from sharing VPN information — a First Amendment question left for another day. Utah legislators have signaled they may revise the law in the next legislative session. But the preliminary injunction sets a meaningful precedent: courts will scrutinize state internet regulations for technical feasibility and extraterritorial overreach. As other states consider similar anti-VPN proposals, this ruling becomes the first judicial marker that technical impossibility is not a compliance challenge — it's a constitutional defect. The pattern here is familiar across digital regulation: legislators write laws targeting a behavior they dislike (anonymity, encryption, VPN use) without understanding the architecture that makes that behavior possible. The result is legislation that either does nothing or forces mass surveillance as a side effect. The court got the technical reality right this time. Whether legislatures learn from it is another question entirely.