I have taped a piece of aluminum foil over every webcam on my laptops/iMac with a large piece of packing tape (making it possible to pull it aside when I do rather frequent video conferences).
I get dismissed as paranoid (or the next question that's asked is "what do you do in front of your computer!"). What they don't understand is that years ago I wrote software for a building access kiosk that involved a one-way video chat, followed with a photograph taken of the visitor. I used an open source library for interacting with the camera. When video was running, the light was on. I had the worst time getting the camera to take a picture, but after a bit of tinkering (read: shooting bullets randomly), I had it working. It was my coworker that noticed the light didn't come on when the picture was being taken. I had done something wrong (so wrong that every few pictures, the camera would stop working and wouldn't recover until the entire machine was rebooted). Though I've been writing software professionally for twenty years or so, I had never wrote code to interact with a web cam and yet had somehow managed to stumble upon this entirely by accident. It gave me the willies, so from that point forward, I covered my cameras with a bit of ugly aluminum foil.
I've never really worried about the microphone, but it would be nice to have some kind of hardware control to disable devices that can be used to record in that manner.
a post it cut with just the glue part works fine, easy to replace and leaves no marks.
If you're that concerned and trust your software stack that little, it wouldn't be that hard to open up the system and physically disconnect the internal microphone, such that you can only use a 3.5mm or Bluetooth microphone. But if you trust your software stack that little, you have bigger problems. Efforts like the one in this article are a good step towards not having to worry about that kind of problem.
http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/18...
Yesterday's news show that some implementations can be unsecure [0].
> But if you trust your software stack that little, you have bigger problems.
I generally trust the software that I run on my main CPU but there are other threats like DMA malware [1] for example.
However, you can disconnect the hardware pretty easy. I've done this on my T400. Took about 5 mins with a Swiss army knife screwdriver (all you need to service a ThinkPad!).
When I use this under linux, it reports an unrecognized keycode; but at the same time the USB device reports as if disconnected, which I can see in dmesg. Close enough for me.