I cam across this article,
http://www.circleid.com/posts/nat_just_say_no/
And was immediately struck by a few issues.
1) A correctly configured firewall would indeed work instead of nat, but, many consumer grade firewalls are really just nat boxes, not routers. Most now have some rudimentry packet filtering, but how many “average” users will configure them properly?
2) It seems to me (being paranoid again) that IPv6 allows to much tracking and identity to an individual machine to ensure privacy to the user. I know IPv6 includes a mechanism to change the specific identifier over time, but how often, and how difficult will this be to implement? Will it be enabled by default on all non static assigned addresses?
Do you all think NAT’s only security is through obscurity? Or is the default lack in incomming initated connection more of a basic packet-filter like function?