I have other hopes to get IoT more secure. Open source firmware, for starters. Support contracts where you don't buy the hardware but buy a working (and insecure isn't working) device.
The problem with IPv6 is that it is a chicken-egg problem. Those who get CGNAT plus native IPv6 are part of the unfortunate bunch who are not using native IPv4 (and therefore miss out on certain IPv4-only services). Meanwhile, the IPv4-only services are causing issues for CGNAT. The logical conclusion is that everyone who currently offers IPv4-only should (and should've been) focusing on adopting native IPv6 dual stack. The continuous procrastination, out of greed and egocentric thinking, is what caused the current situation in the first place.
My ISP tried to shove CGNAT with native IPv6 through my throat. My modem was unstable. BitTorrent didn't work well anymore. I could not use services over LTE anymore (my LTE provider, actually same provider as my cable, used IPv4-only back then; don't know now). I relied on that to work. So they gave me what I had before: IPv4 only. Why not dual stack first?
Though it doesn't give any protection against local scanning.
This is security by realistic approximation of compute capacities and basic probability math.
Aka. good security
Such as github, for example. Something that really surpised me when I setup an IPv6-only virtual machine and then went to clone some projects to setup the host.
People on HN like to say that "security through obscurity" is not security at all. But there's a reason that the military puts its secret stuff out in the middle of nowhere.
Moreover the wasteful norm to rely on /64 subnets and other, similar more practical than privacy-conscious design decisions diminish the potential to stay pseudo-anonymous.
the following operating systems use IPv6 privacy extensions BY DEFAULT:
All versions of Windows after Windows XP
All versions of Mac OS X from 10.7 onward
All versions of iOS since iOS 4.3
All versions of Android since 4.0 (ICS)
Some versions of Linux (and for others it can be easily configured)
For routers, then I have no way to tell. But I would be surprised if stateless addressing wasn't the default on the vast majority of retail routers.[1] https://www.internetsociety.org/blog/2014/12/ipv6-privacy-ad...
Truth is, right now iot devices are protected by nat (your router) and maybe cgnat too (if your isp is good enough and provides that service). With ipv6 those devices will lie exposed to the wan. I hardly see how that’s an improvement.
Also don’t trust regular devices. Windows disabled privacy extensions because of a bug (not sure if it’s fixed already). https://social.technet.microsoft.com/Forums/windows/en-US/57... — I trust my router’s nat much more: it can’t be disabled because of a bug ;-)
You're planning to just get rid of your firewall when you don't need it for NAT anymore?
Some machines’ TCP stacks can be crashed with a single packet. Some IoT devices can be added to botnets. Some get patched.
I think you are blaming too much on ipv6, much of which exists today in the ipv4 world.
You can always set up your router to be a stateful v6 firewall and block wan-to-lan accesses you don’t like or want, much the same way NAT works today, on an outbound-before-inbound model.
Assign themselves addresses randomly ("privacy addresssing") OR Assign themselves addresses based on their EUI64 (a hardware unique ID burned into them at the factory, as in MAC address)
It's feasible to try scanning a known /64 for addresses based on a specific manufacturer's EUI64 block. Maybe Sony brand smart TVs for example. It'd take a bunch of traffic, and thus time, but it could be done.
But it isn't feasible to try scanning the whole /64 for random assigned addresses. You're going to need to send _many terrabytes_ of probe messages to that network. Even over a gigabit network link inside a data centre that might take hours and cost a not insignificant amount of money, to a home or office network it's going to flood the system (causing somebody to make a support call) and take weeks to execute.
Ignore the network practicalities and think just about the economics. Suppose it costs me one millionth of a penny to scan an IP address. I can scan the entire IPv4 Internet for less than $40.
But on the IPv6 Internet, at that price $1 billion only scans me one /64 network. My home has several of those. If you could somehow steal my entire net worth by breaking into a device on my network but first you had to scan all the addresses you're _losing_ money on the deal.
Masquerading NAT is not a security feature. You need state tracking to build a masquerading NAT (so that your residential gateway knows which internal machine to route reply traffic to), and once you have state tracking, you can build a stateful firewall. It doesn't matter which version of IP is carrying the traffic, it still has to go through your gateway before it can get to you, and the gateway can do all the policing you want it to.
If you want certain services on your internal machines to be reachable from the outside over IPv6, you open up that service's port in your gateway's firewall configuration, which is ... exactly what you do for IPv4 too.
OpenWRT (a popular third-party residential gateway firmware) has a stateful IPv4 and IPv6 firewall and DHCPv6/PD support out of the box. You flash it, and if your ISP provides IPv6, you're done. If they don't, you can set up e.g. a 6in4 tunnel with Hurricane Electric, and you're done.
It's not complicated. Yes, you have to learn some things, but they're the same things you had to learn when you were starting out with IPv4.