Two developments this week, one from each side of the border, and they read as the same finding arrived by different tribunals.

On September 24, US District Judge David Barlow issued a preliminary injunction against Utah's SB 73 — the first state law in the country to regulate VPN use for age-verification avoidance. On October 6, Citizen Lab relayed the Globe and Mail's report that Psiphon is preparing to move its operations out of Canada if Bill C-22 — the Lawful Access Act, covered here since it passed the House in June — is enacted in its current form.

One is a court's reasoning written into an order. The other is a company's relocation plan quoted to a national newspaper. Both are arguments about what happens when a law demands a technical capability the technology cannot deliver without breaking the thing it protects.

Psiphon: the exodus gets concrete

The site's June position on C-22 was that Apple, Signal, and VPN providers were threatening to leave. Threats are cheap, and skepticism about them is warranted. What changed this week is the form: a company born in Toronto, spun out of the Citizen Lab in 2006, telling the Globe and Mail through its vice-president Kenzie Elsworthy that it is planning the exit — not as lobbying rhetoric, but as the input to where it will incorporate, host, and hire.

The reasoning is worth stating precisely, because it is an argument about open source running in the opposite direction from the usual one. Psiphon is open source; users and researchers audit its code, and that auditability is part of why twenty million people under censorship regimes trust it. C-22 would require covered electronic service providers to build technical capability for police and CSIS interception — and would prohibit disclosing whether a provider has received a ministerial order. For an open-source tool, that produces a fork Elsworthy laid out plainly: either the added surveillance capability stays confidential, which breaks the transparency the tool's trust rests on, or it becomes visible in public code — inspectable by every repressive government whose users rely on the tool to evade exactly those governments. Either branch, the product is worse for the people it exists for.

Ron Deibert's line about it: C-22 "will make it impossible for a large number of invaluable privacy-preserving tools and applications from operating in Canada."

Windscribe — also Toronto-based, over one hundred million registered accounts — is considering the same exit. They join the earlier warnings from Apple, Meta, Signal, and Proton VPN. The government's defense, via Public Safety Minister Anandasangaree's office: the bill limits compelled decryption and protects against requirements that create systemic vulnerabilities, and most providers would neither qualify as core providers nor face ministerial orders. The operator's counter, which Psiphon made explicitly: uncertainty about which providers are covered forces anyone planning their future to assume they are covered. When classification is ambiguous, the threat of an order does the work of an order.

Note what the bill is still doing in the Senate — second reading, taken up after the summer recess — and which parts this site has already argued: the ESP definition is broad enough to capture a community organization running a Nextcloud instance, and C-22, C-34, and C-36 form one coordinated framework for collection, identity, and data. A hypervisor of your own is not exempt from that logic. It just locates the lawful-access demand somewhere you can see it.

Utah: a court defines the impossibility

SB 73 expanded Utah's age-verification framework with an "actual-location provision" — Utah Code § 78B-3-1002(3) — obligating covered sites to identify users physically located in Utah even when they obfuscate with VPNs or proxies. Judge Barlow's injunction blocks specifically that provision, on dormant Commerce Clause grounds, while the Aylo litigation proceeds.

The mechanics matter. Utah argued the law required only "reasonable efforts" at geolocation — detect masking tools, look at time zones and language settings, ask selected users. The court read the statute as written: the age-verification parts have a reasonableness qualifier; the location part does not. Its conclusion, quoted by EFF: the law "requires entities like Aylo to geolocate its website users with perfection to avoid liability" — strict liability, on a signal that is probabilistic by construction. Both sides agreed perfect geolocation does not exist. So a site avoiding liability under the statute must treat every visitor as potentially in Utah: the order cites the roughly 28 million monthly US users of Aylo's free platforms who would all need age verification to spare a single misattributed Utah visitor.

That is the arithmetic any "detect the obfuscated" mandate produces, and it is not unique to age gates. The same structure — infer a hidden attribute from unreliable signals, attach liability to the inference, watch the inference be wrong — is what age-verification infrastructure generally runs on, and EFF's comments to the Utah Department of Commerce spell out the operational version: the proposed detection heuristics (connection latency, device time zone) are easily skewed by ordinary network conditions, so compliance pushes sites toward more tracking of more users to defend against misclassification — surveillance expanding in the name of privacy enforcement.

Be precise about what was blocked and what was not. The underlying Utah age-verification requirement stays. The separate SB 73 prohibition on covered sites publishing VPN instructions was never challenged in this suit. The state's compliance rules (R152-78B, published September 1, earliest effective date October 8) cannot be enforced as written pending further court action, and Utah legislators are signaling a rewrite next session. Preliminary relief is not a final verdict — it is the court declining to let a technical impossibility take effect while the case is decided.

The shared finding

Put the two next to each other and the pattern is hard to miss. A mandate that requires an impossible capability — perfect geolocation here, interception capability without breaking end-to-end trust there — does not produce a compliance path. It produces exit paths:

  • Block everyone. The Utah statute's structure made nationwide age-checks the only safe posture; the court named that as the over-reach.
  • Leave the jurisdiction. Psiphon's plan, Windscribe's consideration. The service does not vanish — it becomes foreign, with different reachability for its own users.
  • Build the capability and break the product. The path C-22's ambiguity has providers staring down: keep the users, degrade the trust model.

None of these is "comply." That is the tell about the legislative design. And the exits are what actually reshape things downstream: states full of geo-blocked sites, countries full of degraded or departed privacy tools — Psiphon's exit, if it happens, lands hardest not on Canadian lawmakers but on the twenty million users in Iran, Myanmar, Russia, and China who route around their own governments with it. The harm from a capabilities mandate is paid by whoever the mandate was nominally about.

For the operators this site is written for, the C-22 half of the week does not change the calculus; it hardens it. If a law's ESP definition stretches wide enough to be ambiguous about a community's Nextcloud, and ambiguity forces providers to plan as if captured, then the position from June is the standing answer: run the infrastructure where the lawful-access demand arrives somewhere your community can see it, and design what you run to serve your people rather than to retain for anyone who asks. The Utah half adds one lesson that travels: courts are now willing to say the quiet part — that geolocation cannot be perfect, that inference-with-liability is a dragnet in legal clothing. That reasoning will get cited in every jurisdiction drafting "detect the obfuscated" duties. It is worth copying into your own notes now.

Sources: Aylo v. Utah preliminary injunction, Sept 24, 2026 (courtesy copy via Courthouse News); EFF: Court Agrees — Utah's VPN Law Demands a Technical Impossibility; EFF comments on Utah proposed rules R152-78B; Utah State Bulletin, Sept 1, 2026; The Globe and Mail: Psiphon plans to quit Canada; Citizen Lab, Oct 6, 2026; Citizen Lab analysis of Bill C-22; Windscribe: We signed a letter against C-22; News From The States: Utah won't enforce new VPN rules during litigation.