I'm curious about the voice-input feature. In your example, it's activated by clicking the microphone - but could a website activate this without a click (or by tricking a user into clicking something they thought was performing some other function)? Providing the ability to listen in and capture the audio from a user's location without any prompt seems like a huge potential security issue to me.