FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

The Age Check Left the Browser: Why a VPN Extension Wasn’t Enough

The age-verification page had been open for three minutes before I realised the laptop was no longer the device being verified. I had installed a browser VPN extension, refreshed the adult discussion forum and watched my visible location change. Then the site asked me to scan a QR code and continue the facial check on my phone. I scanned it. Safari opened. The camera prompt appeared. Only then did I notice the gap: the extension protecting my laptop browser had no connection to the phone in my hand.

That gap matters more now because age checks are no longer limited to a few obviously adult websites. Since July 25, 2025, UK services carrying pornography and certain other material considered harmful to children have had to introduce stronger age assurance. Ofcom’s 2026 review found the systems operating across pornography, social-media and dating services. (Ofcom)

As the checks spread, VPN interest rose with them. Privacy was a large part of the reaction: adults were not only asking how to reach a page, but how to avoid connecting a sensitive browsing choice to a face, document, bank account or mobile identity. (Arxiv)

A browser extension looked like the restrained answer. It took seconds to install, changed the location seen by the website and left the rest of the laptop alone.

That narrow scope felt reassuring—until the age check stepped outside it.

The short answer

The browser extension had been attractive because it required almost no setup. What I needed was that same simplicity at the device level.

The check began in one tab and continued somewhere else

I had opened the forum to read a discussion classified as adult. Changing the browser’s location did not remove the prompt, probably because the account had already been selected for verification.

The available methods included facial estimation, identity-document matching and a bank-based check. Those choices were not unusual. Ofcom recognises several approaches, including face estimation, photo-ID matching, open banking, card checks, mobile-network checks and digital identity services. (Ofcom)

What the menu did not make obvious was that some methods could leave the original browser.

A face check might work better through a phone camera. Open banking could hand the process to a bank or banking app. A digital identity option might open a separate wallet. Even an email link could launch the device’s default browser rather than the one carrying the extension.

The page was only the starting point.

My extension protected traffic inside the laptop browser. It did not protect Safari on my phone, another browser on the computer or a separate application. Mozilla describes the same basic boundary in its own products: browser-level protection covers Firefox traffic, while a device-level VPN covers other apps and services too. (MDN)

Public questions about extensions often reveal the same mistaken assumption in a more practical form: people install one because they want to protect “the browser,” then discover that the task they are completing does not stay there. (Reddit)

That was my mistake. I had protected the tab. The age check involved a process.

The extension worked until I needed the phone

Inside the laptop browser, the extension appeared to do its job. The forum saw the extension’s exit location instead of my home connection.

Then I selected facial estimation.

The laptop camera produced a dark, badly angled image, so the verification provider offered a QR code for continuing on mobile. That seemed helpful. My phone had a better camera, and the check would probably take less than a minute.

I scanned the code and reached the provider in Safari.

At that moment, the laptop extension stopped mattering. The phone had opened its own connection through my home Wi-Fi. Had I switched to mobile data, the carrier would have handled it instead.

The adult forum was behind the extension. The most sensitive part of the process was not.

I stopped before granting camera access.

I could have forced the check back onto the laptop by improving the lighting and balancing the computer at a better angle. But that would have solved only this one handoff. The next age check might open a banking app or send a link into another browser.

I could not observe the platform’s internal age-classification rules, so there was no useful way to predict which verification path it might demand next. I would have to inspect every transition and remember which apps sat inside the extension’s boundary.

That was too much responsibility for a tool that was supposed to simplify privacy.

The extension was not failing at its advertised task. It was simply protecting a smaller area than the age-verification journey required.

The obvious full VPN added another identity step

A full-device VPN was the clear alternative. It would protect the laptop beyond one browser and could also cover the phone when the verification moved there.

I opened the major provider I had used before. It had years of public history, a large support operation and many server locations.

It also wanted me to sign in again.

I had forgotten the password, so the next steps were email recovery, a reset link and another account login. None of that was alarming by itself. It was simply an awkward answer to the problem in front of me.

I was trying to reduce the number of identity-linked records surrounding one sensitive session. Recovering another long-standing account before protecting it felt like moving in the wrong direction.

The browser extension had been attractive because it required almost no setup. What I needed was that same simplicity at the device level.


The smaller app covered what happened after the click

OnlydogVPN had fewer locations and a shorter public history than the established provider. Those were its clearest limitations.

Its first advantage appeared before the connection began: basic use did not require a conventional email-and-password account.

I connected the laptop, then used a verification code to activate the service on my phone. There was no second password to create and no separate identity-based registration to complete.

That small step changed the shape of the problem. I no longer needed the age check to remain inside one protected browser. Both devices already had a private route.

I returned to the forum and scanned the QR code again.

Safari opened the verification page. The camera request appeared. This time, the phone was already connected through the service.

I completed the facial estimate. The provider returned an adult result, and the forum refreshed on the laptop. The discussion opened.

The task that had broken across two devices now completed as one continuous session:

The forum opened on the laptop. The check moved to the phone. The result returned to the original page.

The full-device connection did not prevent the verification company from seeing the face submitted for estimation. That company needed the image to complete the method I had chosen. What changed was the surrounding network trail. The home internet provider saw encrypted connections to the VPN service rather than separate destinations for the adult forum and the age-verification company.

More importantly, I no longer had to notice every time the process crossed from one browser or device to another.

That was the feature the extension could not provide.

The technology stayed out of the way

The smaller app uses HTTP/3-based transport with additional obfuscation, but the useful part was not the terminology. I did not have to choose a protocol, compare servers or rebuild the connection when the check moved to the phone.

I selected the situation and continued.

The verification page loaded, the result returned and the original discussion opened. The technical layer disappeared into the outcome—which is where it belonged.

Afterward, I followed a link from the discussion to a related health article. A blocked-request counter in the app began to rise as advertising and tracking requests were filtered.

The verification provider had been the visible third party in the session. The counter exposed the quieter ones surrounding an ordinary page load.

That secondary discovery gave me a reason to keep the app installed after the age check was over. The original problem had started with one QR code, but the broader friction was never knowing how many services a single browsing action might involve.

When a browser extension is enough—and when it stops being enough

A browser VPN extension can be useful when the entire task stays inside one browser. It can change the location seen by a website without affecting work software, banking apps or other browsers.

That narrowness is sometimes exactly what the user wants.

Age verification is different because the process can leave the browser with almost no warning. A QR code moves it to a phone. Open banking moves it to a financial service. A mobile check involves a carrier. A digital identity method opens another app.

Once that happens, the user must either accept the unprotected handoff or force every step back into the original browser.

The extension completed the easy part of my session: changing the location of one tab. The device-level app completed the real task: keeping the route protected while the check moved from laptop to phone and back again.

For age-verification privacy, the most important boundary was not the browser window.

It was everything the button asked me to do after I clicked it.

Questions this experience may leave you with

What was actually causing the problem?

The browser extension had been attractive because it required almost no setup. What I needed was that same simplicity at the device level.

Why did the obvious fixes fail?

That small step changed the shape of the problem. I no longer needed the age check to remain inside one protected browser. Both devices already had a private route.

What should you check first?

The age-verification page had been open for three minutes before I realised the laptop was no longer the device being verified. I had installed a browser VPN extension, refreshed the adult discussion forum and watched my visible location change. Then the site asked me to scan a QR code and continue the facial check on my phone. I scanned it. Safari opened. The camera prompt appeared.

What finally changed the result?

The verification page loaded, the result returned and the original discussion opened. The technical layer disappeared into the outcome—which is where it belonged.

What is worth remembering?

Age verification is different because the process can leave the browser with almost no warning. A QR code moves it to a phone. Open banking moves it to a financial service. A mobile check involves a carrier. A digital identity method opens another app.