I think the current boot feature will disallow arbitrary EFI booting. And most mobile device manufacturers do not allow bootloader unlocking for consumers. That being said, there is no guarantee that a determined child will be prevented from apt install git build-essentials and cloning Chromium source code and compile a modified version of Chromium; or from using ncurses and libcurl to hand-make their own tiny browser; or from receiving a premade browser using nc -l 8080 > www.AppImage. As long as the exposed functionalities are Turing-complete and any tiny networking is possible, a determine child will eventually make it happen.
No comments yet.