The reason millions of people open a VPN before browsing has nothing to do with wanting to hide wrongdoing. It is the plain fact that a home router, an internet provider, or a public Wi-Fi network can otherwise assemble a clean, timestamped record of every site visited. A VPN tunnels that traffic through an encrypted connection so the local network sees only noise, not a browsing history. A bill now before Congress threatens to complicate that arrangement by turning some of the same providers people rely on for privacy into enforcement checkpoints.
H.R. 10364 would let a copyright holder petition a court to declare a foreign website a piracy operation, then seek orders compelling large broadband companies, DNS services, and VPN providers to stop US users from reaching it. The providers named in such an order would be left to choose their own "commercially reasonable" method of compliance, whether that means DNS filtering, IP blocking, or another technical approach. For most subscribers, the first sign of trouble will not be a legal notice; it will be a service that simply stops connecting, the kind of everyday glitch people already encounter when a streaming platform mistakes a VPN exit node for proxy traffic. Anyone who has searched for how to fix the Netflix proxy error knows how disorienting an unexplained block can feel, and under this bill similar confusion could stem from a court order rather than a service's internal policy. how to fix the Netflix proxy error
That distinction matters because VPN providers occupy a peculiar position in the privacy ecosystem. Users trust them precisely because they sit between the subscriber and the open internet, encrypting traffic with protocols such as OpenVPN or WireGuard and, ideally, keeping little or no record of where that traffic goes. A provider that must also police court-ordered blocklists becomes something else: a gatekeeper with the technical means to cut off access, not merely to piracy sites but, if an address is misidentified, to anything sharing that infrastructure.
Why Shared Addresses Make Blocking Risky
Large parts of the internet run on shared hosting and shared IP addresses, where one numerical address can serve dozens or hundreds of unrelated domains. Blocking by IP address, one of the "commercially reasonable" options the bill leaves open, risks taking down lawful services that happen to share infrastructure with a site a court has targeted. DNS-level blocking carries a parallel risk: a wrong or outdated domain entry can misdirect an entire category of legitimate traffic. The bill includes notice and correction procedures meant to catch such errors, but correction, by definition, happens after the block is already in effect. For a small business, a nonprofit, or an independent journalist whose site is wrongly swept up, the interval between a mistaken block and its reversal is not an abstraction.
The Trust Question at the Center of VPN Use
VPN services have spent years building a reputation around a simple promise: what you do online is between you and the sites you visit, not your network operator. That promise already depends on trusting a company whose internal logging practices and jurisdiction are not always transparent to the user. A legal regime that compels providers to block court-identified domains adds a new layer to that trust relationship. The practical test for any VPN subscriber going forward is straightforward: will the provider disclose when a block results from a legal order, and will it show the underlying order rather than simply presenting a silent failure? Providers that answer clearly will likely separate themselves from those that treat compliance as an internal, unexplained matter.
Where the Bill Stands
H.R. 10364 remains at the introduced stage, meaning it has not passed committee review, let alone a floor vote, and its final language could shift considerably before any enactment. Its current safeguards, including mechanisms for providers to contest or correct erroneous designations, suggest its authors are aware of the overblocking risk. Whether those safeguards operate quickly enough to prevent real harm to lawful VPN users and the services they rely on is the question that will determine whether this becomes a workable anti-piracy tool or a recurring source of collateral damage to digital rights.