my response is basically not until I understand it...
That was probably a good call, firewalling and (lack of) DHCP especially is quite different so just trying to use v4 concepts on v6 addresses/networks is almost a guaranteed bad time
You already have a bunch of NAT-level suggestions, so I wanted to mention there's an alternative solution: split-horizon DNS, or simply split DNS. Basically, you run a DNS server in your LAN (like pi-hole) which resolves to the private IP, so resolving externally and internally give different results. This way packets don't hit the router at all. You can also do a wildcard like *.something.lan to avoid having to add a record for every service, and only configure your reverse proxy.
Are you saying asymmetric cryptography doesn't exist or is not secure? You may want to collect your research prize and/or bring down the global banking system
I assume it would be something like a key that gets used to generate disposable signatures, not transmitted directly. But I've also been unable to find actual technical details, the article mentions a "GitHub proposal" without linking to it but i couldn't find anything in their repos. Their blog has nothing either
Why do you assume it's one static unchanging token? That's not how cryptography works, you can issue virtually unlimited signatures or challenges/responses without the other party knowing your private key
Yep, and Americans answering with "we're ok because we have AC" is a Don't Look Up moment