Isn't this what caused the, somewhat embarrassing, security update, since someone could host a sound file on their website that would say something like 'delete all files' and the PC would actually do it if the mike was on and speech recognition enabled?