i still think this should be solved at the protocol level. if you want to access the adult stuff, you have to staple a non-identifying zk-proof-of-age to your http/spdy/etc requests, otherwise it all just operates as usual.
The default state should be adult. Kid devices should have something special on setup that makes them kid devices. Or even better, don't have anything like that at all anywhere other than in front of the screen. I really don't see how it is a good thing for a six year old to interact with the Internet in any way.
upgrading to adult content when a credential is provided at the protocol level rather than forcing the operating system to track the state means that consumer operating systems don't have to be secured against their own users.