> http header indicating that the client is a child-locked device
what happens when the request goes through a proxy and that proxy is configured to strip this header?
The Web is HTTPS now, so that can only happen if either the origin server or the user trusts the proxy.
Websites that don't cooperate would need to be blocked by child-locked devices. That part wouldn't be any different from today.