Actually this is true to some point. The very-low-cost cheap implementations don't have any connection tracking modules or only pretty stupid one. But most low- and mid-cost consumer products are trimmed for easiness of usage and therefore contain a lot of such heuristics.
No, I've read such stupid advice way to often.
Only if necessary!
Put in some stupid heuristics and see how it breaks. F.e. most implementations will forward TCP-based DNS replies from any server if a DNS request appeared recently.
Seatbelts usually aren't damaged. But common NAT implementations...
A good host-based packet filter is free of costs. Try Wipfw. If you like to create a discussion about good defaults for clueless homeusers, a set of scripts and maybe a nice guy, this could actually turn into a serious alternative to all those bullshit personal network discos.
I'm not going to pay anything for protecting a simple home user's computer. A router is only needed if two or more have to share the same line.
Better, but not much, and definitely not worth the money.
Sure, that's why you're usually putting exploits in an advertisement propagated through DoubleClick or alike to a lot of usually harmless websites. Why not paying $1000 to target 10s or millions of computers? :-D
You have bandwidth, calculation power and storage space. And especially you're usually clueless about your system.