A virtual private network is, at its core, a way to hide where a person is. That is exactly what makes it useful for getting around a blocked website — and exactly why a bill now moving through the House of Representatives has drawn so much scrutiny.
The measure, H.R. 10364, was introduced on September 14 by Representative Darrell Issa, a California Republican, and referred to the House Judiciary Committee without cosponsors. Its official text has not been published, but a circulating draft reviewed by Ars Technica, obtained through the advocacy group Public Knowledge, lays out what it would do: let federal courts order internet providers, DNS resolvers and VPN services with at least 100,000 monthly U.S. users to block access to websites declared “foreign piracy sites.”
The bill frames the targets carefully. A “foreign online location” is a site run by someone outside the United States, or whose operator cannot be found inside the country after a reasonable investigation, and it must be identifiable by an IP address or domain name. Domestic sites fall outside the new chapter entirely.
The process would run in two steps. First, a copyright owner would ask a court to declare that a site is foreign and primarily designed for piracy, under the ordinary civil standard of a preponderance of the evidence. The owner would have to show it gave, or tried in good faith to give, notice to the site’s operator and domain registrar. Once that label is attached, the owner could seek a separate order naming each network operator that must cut off U.S. access to the site.
In the second stage, the owner’s petition must name every provider it reasonably believes must be included to reduce U.S. access “by a commercially significant amount,” and each named provider can contest being included. Providers would generally get 14 days to object, and judges could shorten that window for time-sensitive content such as live sports or films within a day of release. The draft carves out root nameserver operators, top-level domain registries, and Wi-Fi offered at places like airports, libraries and restaurants.
The VPN provision is the part drawing the loudest objections, and it sits precisely on the question the bill does not answer cleanly: how to determine where a user is.
An ISP block is straightforward because a broadband customer has a fixed address. A VPN erases that. Once a user is routed through a VPN, their location is whatever the VPN server says it is, which makes the whole idea of blocking only “U.S. users” of a service technically slippery. A customer in another country can appear to be in the United States, and an American can appear to be anywhere. Critics argue that a rule broad enough to catch pirates will inevitably catch legitimate users, including people who rely on VPNs for privacy or for work.
The practical difficulties run deeper. A VPN has no fixed pipe to a particular customer the way an ISP does, so compelling a service to block a site may be hard to enforce even with a court order in hand. The draft, for its part, lets providers choose their own blocking methods and delay implementation while they investigate whether a block is cutting off more than intended.
“It threatens user privacy and risks catastrophic collateral damage to the open web,” said Brandon Butler, executive director of the Re:Create coalition.
The DNS piece worries others for a different reason. Meredith Rose, senior policy counsel at Public Knowledge, said applying blocking orders to global DNS resolvers means “one court can cut off access to a website globally, based on a single individual’s filing and an expedited procedure.”
Issa’s earlier draft, from 2025, covered internet providers and DNS resolvers. The circulating text adds VPNs, a sign of how the fight has moved toward the workaround itself.
The bill is the third active site-blocking proposal on Capitol Hill, and it revives a fight that has been simmering since the collapse of the Stop Online Piracy Act and the PROTECT IP Act in 2012. Representative Zoe Lofgren, a California Democrat, introduced the Foreign Anti-Digital Piracy Act in January 2025, and a bipartisan group of senators has been working on a companion effort known as the Block BEARD Act.
Supporters of the Issa bill describe it as a way to move enforcement from the endless whack-a-mole of takedown notices to the infrastructure level. Instead of asking a host to remove one infringing file, the argument goes, a court could ask the operators that carry the traffic to stop users reaching the entire site.
That framing is also the source of the anxiety. A takedown removes a file; a block removes a destination, along with whatever lawful material sits beside the infringing content. The draft’s own safeguards acknowledge the risk, giving providers a defense for good-faith implementation and allowing them to delay blocking to investigate overblocking or maintain their networks.
But the details remain unsettled, and the official text is still unpublished. The fight, for now, is over a document few people have seen and a location problem no one has solved.
“What it amounts to is asking the people who hide your location to be the ones who decide you are where you say you are,” one analyst said. “That is a difficult thing to legislate cleanly.”


