I don’t agree with the risk calculation, I agree that there are potential attack surfaces on the firewall as well. That said, I don’t use firewall as primary or secondary DNS, only as a tertiary “fall-back” DNS if the others are down. And I run none of that “analytics” stuff on the firewall, it’s left to do firewalling/routing, DHCP, backup DNS, and point-to-point VPN termination (I have RA configured but disabled since I don’t need it at the moment). In addition to that, it maintains a dynamic DNS registration and monitors the UPS so it can shut itself down before the battery runs out. I think that’s about it.
So, I’d say that the “exposure surface” is relatively limited, not non-existing, but magnitudes smaller than the “surface” an internal web server that is exposed represents. So, I think a DMZ is the only sensible thing to do if you want to expose something, I don’t expose anything at the moment, but when I do, I use dedicated, isolated networks/DMZs, not necessarily just one DMZ where everything is mixed.
To me, this makes sense. Ultimately, this is somewhat of a “guesswork”, because all somebody needs to do is to find one hole they can get through. If they do, the size of the “attack surface” doesn’t matter. And we don’t know every “weapon” that’s out there and what it can do, so all we can do is guess what the risk is and try our best to deal with it.
That said, for especially “valuable resources”, the firewall isn’t the only layer of protection. You can have all kind of authentication, encryption etc. on the individual devices/computers, which is also a part of the total picture.
I generally accept that if state-level attackers want to get to me, they probably will. They can just send people here to overpower us and take the information the want. There’s a limit to how valuable anything I have is. But, I’d very much like to keep the script kiddies, automated attacks and “opportunistic attackers” in check. That’s my goal, nothing more.