To be clear, the ICE policy isn't an agreed-on Debian-wide opinion, it was just added to the page by a Debian contributor who is concerned about it.
I agree with their concern that hard-coded STUN servers are a potential issue, since the user is not in control of where their traffic goes and whether or not they trust that location.
I agree the suggested best practice doesn't work great for software with a non-technical audience.
Perhaps there needs to be a public ICE pool like the public NTP pool as well as a shared list of known public ICE servers that each software needing stun servers could depend on. Then you could say "cannot contact $foo directly [info link about IPv6, NAT etc], who would you like to try to contact them via?" followed by a list "volunteers" (the pool), Google/Ekiga/GNUnet/Mozilla/etc, custom.