C7.07.3Spoken content as public disclosuredesignresearch

Speaking the content in public is itself a disclosure

Aliases: overhearing · spoken disclosure · public dictation

What it is

Voice input requires saying the content out loud. On transit, in an open office, and in shared homes, that sentence also enters bystanders’ ears. Saying it is disclosure: addresses, one-time codes, contacts, medical detail, and message bodies are no longer secret at the lips, however well the device encrypts afterward. This layer is separate from capture indicators and cloud policy—the audience is the room, not the server.

Why it happens

Sound spreads in air; a screen can be limited by angle and brightness. One-time codes and passwords spoken aloud are a broadcast. Dictating mail hands recipient and wording to the next seat. Even close-talk into a phone can remain intelligible beside you, especially in a quiet carriage. If the system then read-backs a sensitive slot on the loudspeaker, disclosure gets a second round. Encryption and on-device recognition protect the pipe and the store, not the pressure wave. Shoulder surfing at least needs a view of the screen; voice disclosure does not need looking.

Studying it

Measure bystander intelligibility in typical public soundscapes across level, distance, and content type (digits, names, full sentences). Hidden dictation tasks can show whether people spontaneously switch to a keyboard, drop volume, or walk to a corner. Dependent measures include the fraction of sensitive slots a bystander can repeat, and whether speakers realise disclosure already happened. Anechoic recognition scores will not expose this.

Where it stops holding

A private room, or a closed car with one occupant, has low spoken-disclosure risk. Intercoms and counter ordering exist so the other party can hear; “disclosure” cannot be used to ban speaking there. Whisper and bone conduction lower intelligibility and do not cancel it. Labelling all voice unfit for public space would deny legitimate short hands-free commands in the street (“turn at the next exit” is not a secret). The split is content class: authentication secrets and other people’s private data must not be designed as must-speak.

Applying it

  • Do not offer voice input for passwords, one-time codes, or payment PINs; if they have already been spoken in public, treat them as disclosed and re-verify.
  • Mask sensitive slots in default read-back, or use private in-ear read-back; do not broadcast card numbers on a speaker.
  • In public-scene tests, watch whether the task forces people to speak a secret; if so, change the flow rather than telling them to “speak carefully.”

Related

  • Same group: C7.07.1 Capture state must be visible and the indicator must not be disableable · C7.07.2 Bystanders must not be treated as the user
  • Adjacent: C7.06 Hands-Free and Eyes-Free Use · C7.16 Visible Feedback for Voice Input
  • Search: overhearing · spoken disclosure · public voice input

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/C7.07.3