H.R. 10364

Proposed Copyright Bill Could Turn VPNs Into Blocking Tools

Proposed Copyright Bill Could Turn VPNs Into Blocking Tools

A VPN exists, in large part, to stop a home router or an internet provider from compiling a tidy record of every site a person visits. That basic promise is now facing a legislative test. A bill introduced in the US Congress, H.R. 10364, would give copyright holders a legal path to label a foreign website a piracy site and then push broadband companies, DNS services, and VPN providers to block American users from reaching it.

The mechanism matters because of where it places the point of control. Privacy tools do not operate in a vacuum; they depend on an intermediary willing to carry traffic without interference. Once that intermediary is handed a court order, it must decide how to comply, and the law leaves the method up to each provider's judgment, requiring only that the response be "commercially reasonable." For ordinary users, this is a reminder that even encrypted, logless-by-design tools sit inside a regulatory environment that can shift their behavior overnight. It's also worth remembering that technical failures and legal blocks can look identical from the outside, which is one reason people researching why a VPN might not work on your Wi-Fi sometimes discover the cause is not a router setting at all, but an upstream order the provider was compelled to follow.

How the Blocking Chain Would Work

Under the proposed framework, a rights holder would ask a court to designate a specific foreign location as a piracy site. If granted, the designation allows the rights holder to pursue blocking orders against large infrastructure providers, a category that explicitly includes major VPN services alongside broadband and DNS operators. Each provider then selects its own technical approach, whether that means filtering a domain, dropping specific routes, or some other method the provider considers reasonable under the circumstances. The bill does include notice requirements and a correction process, intended to let providers flag mistakes and reverse wrongful blocks.

The practical risk sits in the gap between a block going into effect and a correction being processed. Piracy sites frequently share infrastructure with unrelated services, rotate domains, or sit behind the same IP address as legitimate businesses. A block aimed at one target can sweep in another, and the bill's remedy arrives after the fact, not before. For a VPN provider operating at scale, that means occasionally choosing between swift compliance and the risk of disrupting lawful traffic, a decision made more urgent by the threat of enforcement rather than by a verified, narrow match between order and target.

Why the Intermediary Problem Is Not New

VPN technology grew out of a straightforward need: encrypt traffic between a device and a remote server so that networks in between, including the Wi-Fi at a coffee shop or an internet provider's own equipment, cannot see the destination or content of that traffic. Tunneling protocols and modern encryption standards solved the visibility problem effectively. What they never solved, because no technology can, is the question of who controls the server at the other end of the tunnel. That server belongs to a company, and the company exists under a legal jurisdiction, which means it can be compelled to act.

This is why jurisdiction and corporate structure matter as much as encryption strength when evaluating a privacy tool. A VPN can shield a user from local network surveillance while still being legally reachable by courts in the country where it operates or does business. H.R. 10364 does not weaken encryption or demand backdoors; it targets the provider's willingness, or obligation, to route traffic to a designated destination at all.

What to Ask Before Trusting a Provider

The bill remains at the introduced stage, far from guaranteed passage, and its safeguards suggest lawmakers anticipated some of the overreach concerns raised by digital rights advocates. Still, the episode offers a useful test for any privacy service.

  • Will the provider disclose when a legal order affects routing or access, rather than silently absorbing the change?
  • Does the provider commit to sharing the underlying order, where legally permitted, so users can judge its scope?
  • How quickly does the provider say it will act on correction requests if a block proves overbroad?

Transparency on these points will not stop a valid court order. It will, however, tell users whether their chosen intermediary treats them as a client deserving an explanation or as a pass-through node with no obligation to explain what changed and why.