Assign themselves addresses randomly ("privacy addresssing") OR Assign themselves addresses based on their EUI64 (a hardware unique ID burned into them at the factory, as in MAC address)
It's feasible to try scanning a known /64 for addresses based on a specific manufacturer's EUI64 block. Maybe Sony brand smart TVs for example. It'd take a bunch of traffic, and thus time, but it could be done.
But it isn't feasible to try scanning the whole /64 for random assigned addresses. You're going to need to send _many terrabytes_ of probe messages to that network. Even over a gigabit network link inside a data centre that might take hours and cost a not insignificant amount of money, to a home or office network it's going to flood the system (causing somebody to make a support call) and take weeks to execute.
Ignore the network practicalities and think just about the economics. Suppose it costs me one millionth of a penny to scan an IP address. I can scan the entire IPv4 Internet for less than $40.
But on the IPv6 Internet, at that price $1 billion only scans me one /64 network. My home has several of those. If you could somehow steal my entire net worth by breaking into a device on my network but first you had to scan all the addresses you're _losing_ money on the deal.
Masquerading NAT is not a security feature. You need state tracking to build a masquerading NAT (so that your residential gateway knows which internal machine to route reply traffic to), and once you have state tracking, you can build a stateful firewall. It doesn't matter which version of IP is carrying the traffic, it still has to go through your gateway before it can get to you, and the gateway can do all the policing you want it to.
If you want certain services on your internal machines to be reachable from the outside over IPv6, you open up that service's port in your gateway's firewall configuration, which is ... exactly what you do for IPv4 too.
OpenWRT (a popular third-party residential gateway firmware) has a stateful IPv4 and IPv6 firewall and DHCPv6/PD support out of the box. You flash it, and if your ISP provides IPv6, you're done. If they don't, you can set up e.g. a 6in4 tunnel with Hurricane Electric, and you're done.
It's not complicated. Yes, you have to learn some things, but they're the same things you had to learn when you were starting out with IPv4.
Truth is, right now iot devices are protected by nat (your router) and maybe cgnat too (if your isp is good enough and provides that service). With ipv6 those devices will lie exposed to the wan. I hardly see how that’s an improvement.
Also don’t trust regular devices. Windows disabled privacy extensions because of a bug (not sure if it’s fixed already). https://social.technet.microsoft.com/Forums/windows/en-US/57... — I trust my router’s nat much more: it can’t be disabled because of a bug ;-)
You're planning to just get rid of your firewall when you don't need it for NAT anymore?
Some machines’ TCP stacks can be crashed with a single packet. Some IoT devices can be added to botnets. Some get patched.
I think you are blaming too much on ipv6, much of which exists today in the ipv4 world.
You can always set up your router to be a stateful v6 firewall and block wan-to-lan accesses you don’t like or want, much the same way NAT works today, on an outbound-before-inbound model.