Agent · /llms.txt SHA-256
← Writing
23 September 2026 Comment · Utah Rule R152-78B

Age verification is a location problem.

We filed a comment on Utah's proposed Rule R152-78B on 22 September 2026.

False-colour Copernicus Sentinel-2 image of Utah's Great Salt Lake: water deep blue, vegetation red, salt flats white, with the Lucin Cutoff causeway dividing the lake's two basins

Utah’s Great Salt Lake, 17 March 2019. False colour, near-infrared: vegetation reads red. Contains modified Copernicus Sentinel data (2019), processed by ESA. CC BY-SA 3.0 IGO.

Utah's age-verification law, SB 73, requires websites deemed to have adult content to check that a visitor is an adult. The Division of Consumer Protection has proposed a rule to implement it, open for comment until 1 October. The attention is on the age check: what counts as verification, who holds the ID, whether it survives the First Amendment.

The age check is not the part that is easy to break. The location check is.

A person outside Utah is outside the statute. A person inside it gets age-checked. Before any age verification runs, something has to answer a different question: is this visitor in Utah?

The rule sets the same 95% accuracy standard for both determinations. It specifies how to measure only one of them.

The rule says how to measure age, not location

For age, the rule gives an error formula: false positives over false positives plus true negatives, which resolves to the share of actual minors a system lets through. It caps that rate by the person's real age: 2% at seventeen, 1% at sixteen, 0.1% at fifteen and below. It requires a way for someone to challenge a wrong result.

For location, the rule requires a system “calculated to enable the commercial entity to identify with at least 95% accuracy whether a person attempting to access a website… is in Utah.” There is no formula, no evaluation population, no error direction, and no way for a person wrongly judged to be in Utah to challenge it.

The Division's fiscal analysis prices geolocation and obfuscation detection together at about a cent per person, against one to twelve cents per age-verification attempt.

A cent is our price too, so the comparison is worth spelling out. We charge a cent per active user per month, with unlimited determinations, for a user inside an app where the determination is measured and signed on the device. The fiscal note's cent buys a single anonymous web visit. At that price the only available method is an IP lookup against a commercial geolocation database. A VPN defeats it, which is why this rule exists.

A 2023 study tested the major databases against 6.3 million ground-truth addresses. They missed by 376 km on average, and disagreed with each other by 620 km. Utah is about 435 km across.

Security is a chain; the weakest link breaks it.

— Bruce Schneier, The Process of Security, 2000

A control is defeated at its cheapest point. Apple's documentation shows this. You have less than a one in a million chance of unlocking someone else's iPhone with Face ID, and a one in fifty thousand chance with Touch ID. Both fall back to the passcode after five failed attempts. If you want to get into the phone, don't try to beat the biometric. Let it fail five times and attack the passcode.

The Utah rule works the same way. It specifies the age determination to a tenth of a percent and prices the location determination as an IP lookup. If you want access, don't try to beat facial age estimation or a document check. Turn on a VPN and you are judged to be outside Utah, and never asked for either.

The rule names three signals, and the visitor controls all three

Section 201(2)(b) says an entity may analyze “latent signals,” including connection latency, the device's time zone, and other data the browser transmits. “Latent” suggests something a device gives off passively. None of the three works that way.

Time zone is a value the browser reads from the operating system, and changing it is a settings change. Latency reflects routing, and commercial VPNs run exit nodes in every major population center, so a nearby exit produces local-looking latency. User agent, language headers, and screen metrics are client-controlled and routinely normalized by privacy tools that ordinary people use for ordinary reasons.

There is a second problem. Section 103(4) defines the detection system as a method for identifying whether a location is masked or whether a person is in Utah. Those are different jobs. Spotting a proxied connection is pattern recognition on network traffic. Determining where someone is means measuring something physical. A system can do the first perfectly and tell you nothing about the second. A visitor correctly flagged as using a VPN might be in Provo or in Frankfurt.

When the rule is unsure, it asks the visitor

Once obfuscation is detected, the rule gives the operator three options: ask the visitor to share their location, require them to turn off the VPN and age-verify if they are in Utah, or age-verify without more.

Only the request to share location tries to answer the question the rule has just raised. The other two send the visitor to age verification, which is a different determination.

Requiring the visitor to turn off the VPN is also circular. It applies “if the person is located in Utah,” but whether the visitor is in Utah is exactly what the obfuscation put in doubt. The operator would have to already know the answer, and the rule never says how to find it.

So an operator who wants to establish location has one option, and it is to ask the visitor. In a browser that means the Geolocation API, which returns whatever the operating system reports and can be overridden from developer tools with no special privileges. This option is triggered by evidence that the visitor is concealing where they are. It then asks that visitor for the fact in dispute.

Data reported by the party being assessed is worth that party's honesty and no more.

Both sides of the lawsuit are wrong about the technology

Aylo, Pornhub's parent company, is suing Utah over this law.

The complaint says at paragraph 6 that this is “not a temporary technological limitation awaiting a solution” but “an inherent feature of how VPNs and proxy servers work.” That does not follow. Masking relays traffic through an intermediary, so the server sees the intermediary's address. It defeats any method that infers position from the connection. It says nothing about a method that measures position, because physical position is not a property of the network path. A device in Provo is in Provo whether its packets arrive from Provo, New York, or Zurich.

Paragraph 43 calls GPS, WiFi, and cell-tower positioning “susceptible to manipulation.” That is true of raw operating-system signals, which any app can override with a mock-location tool. It is not true of a measurement made on the device across many sensors at once, signed by a key held in hardware the app cannot reach, on a device and build the platform vendor has attested. The filing does not consider that category. It is the category we build in.

The State's reported position is also wrong. Press coverage has the Attorney General's Office suggesting compliance should not be difficult. Most traffic this rule covers arrives through a browser, where resolving a state boundary requires the visitor's consent and the position they share is one input among many. The answer will often be right. What a manipulated input changes is the confidence that answer deserves, and a page has far fewer independent signals to constrain it than an app does.

It is harder than the State says, and possible in a way Aylo says it is not. The two claims lead to different rules. If location is inherently unknowable, no standard can be written. If it is unknowable by inference and knowable by measurement on an attested device, the standard depends on which channel the operator is serving.

What a location standard should require

A determination that survives an adversary who owns the device rests on two separate proofs.

One is statistical. Sensor fusion draws on satellite, inertial, barometric, magnetic, and radio signals, sampled continuously and checked against each other. An adversary has to forge all of them at the same instant, consistently with each other. That is the same argument as a published false-accept rate. Apple publishes its Face ID and Touch ID figures with the conditions each one holds under, and says where Face ID degrades: twins and siblings who look like the enrolled user, and children under thirteen. That is what a usable threshold looks like: a stated probability, from a named method, with its limits given.

The other is cryptographic. The result came from the device it claims, signed by a key held in hardware the app cannot reach, the Secure Enclave on iOS and StrongBox on Android. App Attest and Play Integrity establish that the hardware is real, the operating system is not rooted, and the code is the code the developer shipped.

Neither substitutes for the other, which is why one percentage cannot stand for both. A 95% figure cannot say whether it describes measurement quality, device integrity, or some blend of the two.

So we asked the Division to require properties a third party can check from the result itself: a stated probability with the method named, authenticity, a signing key in device hardware, platform attestation of the device and the code, freshness, whether the method declines to answer when it cannot answer, and whether any raw position data left the device. Properties admit methods that do not exist yet and exclude methods that only assert.

We also asked for something the rule has no concept of: an outcome for “we do not know.” Right now there are two outcomes, correct and incorrect, and that rewards guessing. An operator with no way to record “could not determine” has every incentive to produce an answer rather than withhold one. Inability to determine is also not one condition. A device that has just woken with no position fix warrants a retry. A detected manipulation attempt is information, and it is the exact finding the provision exists to produce. A framework that logs both as “unable to verify” throws away the useful one.

This is not only about Utah

About twenty states now have social media or adult-content age laws, nearly all in litigation, and the litigation is about the First Amendment. Every one of those laws is scoped by geography. Texas's app store law reaches “an individual in this state,” a presence test rather than a residency test. None of them says how you would know. Utah's rule is the most specified of the set, and its location half is a bare number. Every state that follows will copy the same gap.

Europe is heading for the same problem from the other direction, as France, Denmark and Austria land on different national minimum ages inside a single market with free movement. The EU's own age-verification architecture is already device-based and discloses nothing but the predicate, which is the right shape. It proves age without proving where you are.

Without a way to establish location, operators will age-verify everyone rather than risk getting it wrong. With a determination that holds up against a VPN, an operator can apply a jurisdiction's rules to the visitors that jurisdiction covers and leave everyone else alone.

Where we are

We build proof of location because it is the missing primitive. Most checks a regulator asks for are conditional on where the person is: age here, a licence in gaming, sanctions in payments. The location answer decides whether the other check is required at all, and a wrong location answer makes that check irrelevant no matter how well it runs. In this rule, proof of location is the proof behind the proof of age.

The measurement is made on the device, signed by a hardware key, and returned as yes, no, or indeterminate. No coordinates are transmitted.

  • Mobile SDK, live. Inside an app it resolves country and state with no location permission and no prompt to the visitor, and a VPN does not affect it. That is the determination this rule needs, and it exists today.
  • Browser SDK, live, by request. It resolves country without a permission. Resolving state needs the visitor's consent, and with that consent it also detects when the shared position has been manipulated. What it cannot do is recover the visitor's true state after that, which an app can.
  • Location Factor Authentication. For the browser case, location becomes a factor at sign-in the way a passkey or a one-time code is. A site issues a location challenge. The visitor's enrolled phone answers it and returns a signed verdict on the region, and nothing finer. Coordinates never leave the device.

Age verification is only as good as the location check that decides who has to take it.