> But never well enough, it seems.
"Never well enough" for stopping teens (and pre-teens) installing access tokens?
Has any adolescent in history ever managed to so much as spoof someone else's session cookie *on their phone*? And if so, when? If this is a flaw which comes up once every five iOS versions or whatever, who cares?
> Kids will beg/borrow/steal their parents / older siblings ... etc.
They occasionally get alcohol, too, despite restrictions. The point is to *mostly* stop them.
And it's not like the payment systems have not already solved the same problem.
> All that does is punish the innocent.
Which is literally something I'm trying to solve with my suggestion up-thread: here's a way to do age attestation that doesn't need to punish anyone.