@dckc @fdr @lotte @spritely It's dangerous probably to directly expose machines over ipv6, but is there any reason it should be if our software stacks better designed, if we had a more capability-oriented worldview?
I think often of Marc Stiegler's "perimeter security is eggshell security" which critiques many things, including a firewall-oriented perspective http://www.skyhunter.com/marcs/ewalnut.html#SEC44
See the "eggshell defense" subsection