Edit: To clarify, I'm only talking about the sandbox here, I'm aware that there is opt-in stuff and that there is open source code guarding the activation of that specific module, i'd argue that this isn't part of the sandbox though.
Edit: To clarify, I'm only talking about the sandbox here, I'm aware that there is opt-in stuff and that there is open source code guarding the activation of that specific module, i'd argue that this isn't part of the sandbox though.
My phrasing of "anytime" was perhaps misleading, I'm aware that the module is guarded by open source code that activates it under specific conditions.
However I was talking about the sandbox, and when the module is running it does have access to the microphone without asking. The code guarding the activation of the module isn't relevant in this context.
> The hotword module has the same privileges as any website (except that it automatically has access to the microphone).
My original post was perhaps misleading, I'm only talking about the sandbox here, I'm aware that there is opt-in stuff and that there is open source code guarding the activation of that specific module, i'd argue that this isn't part of the sandbox though.
It makes me think of how Windows with it's very comprehensive mandatory access control remained vulnerable to simple attacks because the ACLs were too complicated. Thus application developers would request overly broad permissions, defeating the usefulness of the security model.
Seems to me that having too many difficult to use security features can be as bad as or worse than too little security.