I have some huge problems with that reasoning.
First off, regarding whether the programs can do anything malicious, where is
the cutoff point? Is it battery backed SRAM introduced in the third
generation? Or is it memory cards that store save data for many games at
once, introduced in the fifth generation? or does the cutoff point not occur
until online connectivity was introduced in the Dreamcast?
Second off, with exchange of ROM files being easy and common, you don't need
a "highly complicated setup" to make changes. With the Retrode, you don't
even need anything all that complicated to read the ROM directly off of a
cartridge. The only complicating factor is copyright and the fact that all of
these games are proprietary. All you need to do to see this is look at the
many "ROM hacks" floating around the Internet, most of them being offered as
"patches" to avoid getting sued the heck out of by Nintendo or Sega or
whoever holds the copyright to the game they're hacking. Even people who
don't want to make changes often are restricted by copyright from (legally)
doing what they want to do with ROM files: share.
Third, even if it was still nearly impossible to read the cartridges, I don't
see how that makes an additional restriction (being proprietary) ethically
acceptable all of a sudden. This type of argument could be used for virtually
anything. For example: nobody but the author knows how to compile program X
because it's such a horrible mess of a dozen different programming languages
intertwined in spaghetti code, so it's OK for it to be proprietary.