Denying the ISPs trivial inspection into the structure of home networks, OTOH, is a major benefit and maybe a concrete downside to adopting IPv6 locally.
With IPv6, users can put their devices out on the wild-west open internet without needing any kind of NAT or firewall for protection.
The large number of open access points in the wild points out the danger here -- most consumers know nothing about network security and will set up their home network with dozens of IoT devices all on the public internet behind their ISP's non-firewalling router because they can, and everything works.
They'll do whatever makes support easiest until they are forced to do otherwise by regulation or bad press.
Everyone seems to misunderstand that I am not advocating for what should be/should have been, but instead providing the benefits of how things played out given the reality of the world.
Abstract:
pwnat, pronounced "poe-nat", is a tool that allows any
number of clients behind NATs to communicate with a
server behind a separate NAT with *no* port forwarding
*no* DMZ setup, and *no* 3rd party involvement. The server
does not need to know anything about the clients trying
to connect.
(0) https://samy.pl/pwnat/In other words, get sent to a domain that initiates the knock sequence. Other machine in waiting responds, and NAT traversal takes over, to any machines inside NAT.
The only real question is how much code is actually required to start this.
So yes, it looks like some sort of further in-depth hackery would be required, or planting some sort of SBC in the building on the network. It's quite a bit more infeasible than I had initially thought.