What makes clock gating of SPI & I2S difficult?
As an example component, here's a SPI mux by Maxim that has 8 separately-controlled SPST switches for <= $3.30 (probably much cheaper at scale). http://www.maximintegrated.com/datasheet/index.mvp/id/1281 So, if you utilize this fully, you could clock-gate 8 separate SPI components for < $0.42 each, right?
Is a mux the wrong way to do it? What's the proper implementation?
The MUX you link to would likely allow them to disconnect the microphone easily, BUT it wouldn't prevent the noise on it's own in the first place. There'd likely still be a signal at 24MHZ that shows just blank audio, it'd be better for security of course but doesn't fix the leakage.
Keeping the clocks running makes it easier to start streaming audio. Otherwise, restarting the clocks means you have to wait for them to settle before pulling the ADC out of reset. After that you have to flush buffers, align samples for phase/latency, and artificially zero the input stream until the rest of the circuitry settles down. Keeping the clocks running means turning the input on or off is only a matter of passing the audio samples or passing zeros.
Also, if the system isn't grounded properly then the analog input could definitely find its way onto the 24.576MHz MClk. In the audio world, digital noise leaking into the audio stream is universally bad while no one usually bats an eye at analog leaking into the digital domain.
It's definitely lazy from a security standpoint but probably not intentional.
It can be easy to route noise through an area the designer didn't intend with a simple solder blob or a defective power supply bypass capacitor. 24MHz could just be a frequency of a crystal oscillator.
I'd want to know the actual power level of the transmission, but to measure that accurately, you'd want to put the laptop in a shielded chamber.