Yet all of this can be easily defeated with soft language. The basic check "what's the password/verification word" will defeat this every time. This is basically opsec that we taught my grandparents, who were in their 90s. Its doable.
Yes but that's more of a mitigation than prevention. It's an additional step, you have to remember to do it, and under the pressure of the situation you might easily forget to do it.
1. Kid tells password to parent in person.
2. From then on: when kid calls parent, if kid requests anything sensitive, parent ask for the password, and kid must provide it.
3. Password is never mentioned over the phone in any other situation.
How would anyone be able to extract the password from the kid?