Alright. Most consumer routers do both NAT and firewalling, especially in their stock configurations, but I can drag one out and disable the firewall on it to test with.
I hooked the router up to my network, and then hooked my laptop up behind the router. The router's WAN address is 192.168.4.101, and my laptop got 192.168.1.9. If I try to connect outwards from my laptop, the connection appears to come from the router's WAN address:
18:47:04.854781 IP 192.168.4.101.45598 > 209.216.230.240.80: Flags [S], seq 3415044640, win 29200, options [...], length 0
18:47:04.988960 IP 209.216.230.240.80 > 192.168.4.101.45598: Flags [S.], seq 2572527210, ack 3415044641, win 65535, options [...], length 0
18:47:04.990322 IP 192.168.4.101.45598 > 209.216.230.240.80: Flags [.], ack 1, win 913, options [...], length 0
That confirms that NAT is working. Next, I'll try to connect to a server on my laptop from outside the router:
18:49:32.400441 IP 192.168.4.2.58084 > 192.168.1.9.9999: Flags [S], seq 2394060892, win 64240, options [...], length 0
18:49:32.431718 IP 192.168.1.9.9999 > 192.168.4.2.58084: Flags [S.], seq 3958961179, ack 2394060893, win 28960, options [...], length 0
18:49:32.432013 IP 192.168.4.2.58084 > 192.168.1.9.9999: Flags [.], ack 1, win 2008, options [...], length 0
You can see it works completely fine. The inbound connection successfully completes even while the router is NATing outbound connections, and this is on a regular consumer router.
> Yes which is my chief complaint. Not getting rid of NAT, pushing the firewall to the client.
v6 doesn't necessarily push the firewall to clients. You can and generally do still firewall on your router.
> Why are we the entirety of the 64 subnet? You can use some knowledge about networks to cut this down a lot. Just the one knowing a network is there is enough.
I know you can cut the search space down somewhat, but it's still massively bigger than v4, and therefore it's still going to be harder to find servers via scanning in v6 than in v4. NAT won't help in the slightest with this.
I'm not trying to suggest that anybody's security should (or even could) rely on hiding their hosts in a big sparse network; you should obviously run a firewall, and pretty much every consumer router does in fact do that. I'm just saying that if somebody does run without a firewall -- or deliberately configures it to permit inbound connections -- the large address space reduces exposure simply by making it harder to find any listening servers.
> What does this even mean? How does a computer get a vaccination?
It means that there's some conceptual similarities between the two situations. With vaccines, it's possible to completely stamp out a disease even if a small percentage of vaccinated people still catch the disease in question.
Similarly, even if a small number of servers are found by brute force scanning, so long as it remains hard enough to do so on average brute force scanning will remain an unviable method of spreading malware. This won't eliminate malware in general (because there are plenty of other infection routes to use) but any malware that relies on exploiting random vulnerable servers is going to have a much harder time in v6, not a much easier time as you assumed above.