Would someone be able to comment on this: Why is it not possible to require websites that wish to market to children to be certified as "child safe". Such sites would be audited by an independent entity that would grant them some form of encrypted key. These could be in age bands, e.g. We do this for many other things, from toys to public venues. Parents could then set their child's device to only allow access to sit…
This seems to be a situation where the stated problem (protect children) is different to the actual problem (surveillance). Your proposal doesn't solve the actual problem.
We can fight this by supporting child protection mechanisms that don't act as mass surveillance, such as the one in California that merely reports whether root said the user is a child, and fighting ones that do, such as the one in New York that checks your ID.