> 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it
Good. Parental/school controls don't belong on the device. They belong on whatever the device connects to.
That would be parental/school networks.
If you don't want your kids to connect to things then don't let your kids have devices that connect to things.
> 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk
The direct security risk is using Google in the first place.
> 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exploiting this, and machines being compromised and escalations
There's nothing in that statement that relates specifically to kids.
> Your argument seems like arguing that there should be no local access permissions on files and just let the network handle everything.
Quite the contrary. Your local files are given to you by your local device. It's up to your local device to ensure that those files are properly access controlled.
But things on your network are given to you by your network. It should be up to your network to ensure that those things are properly access controlled. It should be up to you to ensure that you don't connect to networks which don't have proper access control.
> school, at least in my region, requires devices directly since 4th grade
If school requires things then school should provide things.
> indirectly even earlier for homework
Homework should be done at home. Are you saying that you don't have control over which devices on your network are able to access which things online? You should fix that.
And locking down the primary device a kid has access to creates the lure of the forbidden; that won't last any longer than their access to another device without those restrictions. That also creates an environment where if they do find something they really ought to be able to talk an adult about, they can't talk to a parent about it because they'll be in trouble (and get their friends in trouble).
One of the widely studied aspects of child psychology is how to instill guidelines that last even when they're elsewhere without any enforcement other than self-enforcement.
Good. Parental/school controls don't belong on the device. They belong on whatever the device connects to.
That would be parental/school networks.
If you don't want your kids to connect to things then don't let your kids have devices that connect to things.
> 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk
The direct security risk is using Google in the first place.
> 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exploiting this, and machines being compromised and escalations
There's nothing in that statement that relates specifically to kids.