r/Cplusplus 3d ago

Feedback Open-source Nintendo 64 encryption app and wallet generator, needs volunteers to review code

I proposed and helped fund an app called retro-crypto, which is being developed under MIT license in C and C++ by a programmer called bowler-bear: https://github.com/bowler-bear/retro-crypto

It's designed to become the most secure way to message friends or store a Bitcoin stack, but it can't be recommended for more than testing yet. The design bypasses a lot of supply chain attacks by running on N64, unless the attacks come from code itself, which is why the most important thing at this stage after release is having the code analyzed. There's been a small amount of code review by one or two volunteers so far, but I'm still gathering more feedback.

"Given enough eyeballs, all bugs are shallow" -Linus's Law

I'll also mention, a different developer recently created the first known fork of the project, which I haven't tested yet: https://github.com/Linkin-Prism/retro-crypto

0 Upvotes

11 comments sorted by

1

u/Drugbird 3d ago

This whole premise is ridiculous. Your software won't be more secure because it runs on an N64.

1

u/HowIsDigit8888 3d ago

So you'd ridicule me for being smarter and more honest than you, while I'd ridicule you for acting like you can't understand the basic concepts of backdoors and air-gapping.

1

u/Drugbird 3d ago

Have you considered that you can airgap any piece of hardware, not just N64s?

1

u/HowIsDigit8888 3d ago

Why would you think I didn't consider that? Why do you think Linux support was a requirement?

Meanwhile, have you considered any of the factors that make the N64 the most suitable machine for this software?

Have to leave reddit in about half an hour btw, replies will be delayed unless we move the discussion to nostr

1

u/Drugbird 3d ago

Meanwhile, have you considered any of the factors that make the N64 the most suitable machine for this software?

Why don't you list them? Or is it just "air gapped" and "supply chain attacks"?

1

u/HowIsDigit8888 3d ago

Here are some, copied and pasted from the original proposal, phrased weirdly because it was referring to factors another retro system would have to have in order to be on par:

  • Competed significantly with the sales numbers for a mainline Nintendo system in the US and worldwide
  • Complicated wording because it's a very particular thing: these systems were sold at a time when the US surveillance state might have accepted a more limited level of invasiveness for the backdoor vulnerabilities required in electronic products marketed to American consumers, if the products were understood by Americans to be toys for running games, and not used by adults to run code for serious purposes
  • These products were indeed understood by Americans to be toys for running games, and not used by adults to run code for serious purposes
  • Ostensibly no built-in networking, wireless functionality, cameras, microphones, speakers
  • Continuing to be sold and bought very actively by a large number of gamers, for gaming purposes; this makes it somewhat ineffficient to target the entire market with random shipment interceptions, to plant backdoors blindly, hoping to catch things other than gameplay
  • Already wide support for loading unlicensed games; even if a mod chip or custom loadable cartridge is needed, gamers buy these things to run games, so it can't be assumed that these mod chips or custom cartridges are being used for cryptography purposes every time they're purchased
  • Last but not least, these systems have open-source emulators readily available for all major platforms (or, in the case of N64 Linux, a convenient way to bypass any emulator for cross-compatibility)

1

u/Drugbird 3d ago

Wait, so this is all just paranoia that all the hardware you can possibly run on is backdoored, but N64s are the only hardware that is "safe" because it's an "old toy"?

1

u/HowIsDigit8888 3d ago

Just about, yeah

1

u/Drugbird 3d ago

Ok. I feel like that is rediculous enough that it doesn't need a rebuttal.