Metaverse will face security threats as old as the web, says Microsoft exec

HoloLens
HoloLens (Image credit: Windows Central)

What you need to know

  • Microsoft's Charlie Bell discussed securing the metaverse in a recent blog post.
  • Bell highlights that the metaverse will face similar security threats to existing technology, including impersonation and data theft.
  • The executive calls for organizations to work together and to implement security policies now before the metaverse takes off.

Microsoft Executive Vice President, Security, Compliance, Identity, and Management Charlie Bell discussed those risks in a blog post. The exact method of attacks within the metaverse may differ to those seen through email or other current types of technology, but the general concepts will remain the same. Regardless of the medium, malicious actors will try to use deception and human error to gain access to information.

Trying to deceive people isn't new. Bell recalls the early days of email fraud as an example. Of course, email fraud and phishing schemes are still common today. Attacks in the metaverse will use different entry points, but they'll look familiar.

"There is an inherent social engineering advantage with the novelty of any new technology," said Bell. "In the metaverse, fraud and phishing attacks targeting your identity could come from a familiar face – literally – like an avatar who impersonates your coworker, instead of a misleading domain name or email address."

To combat threats in the metaverse, Bell encourages organizations to learn from the lessons of the past. "Organizations need to know that adopting metaverse-enabled apps and experiences won't upend their identity and access control," said Bell. "This means we have to make identity manageable for enterprises in this new world."

The executive encourages multi-factor authentication, passwordless authentication, and other security measures. Many of these are already in use, so IT admins should be familiar with them.

Bell concludes his post with a call to work together. Since there won't be a single metaverse platform, general security measures and policies will be important.

"The problems of yesterday's and today's Internet — impersonation, attempts to steal credentials, social engineering, nation state espionage, inevitable vulnerabilities — will be with us in the metaverse," said Bell. "And it will take the same security community of good faith, norms and teamwork to anticipate and respond to them."

Sean Endicott
News Writer and apps editor

Sean Endicott is a news writer and apps editor for Windows Central with 11+ years of experience. A Nottingham Trent journalism graduate, Sean has covered the industry’s arc from the Lumia era to the launch of Windows 11 and generative AI. Having started at Thrifter, he uses his expertise in price tracking to help readers find genuine hardware value.

Beyond tech news, Sean is a UK sports media pioneer. In 2017, he became one of the first to stream via smartphone and is an expert in AP Capture systems. A tech-forward coach, he was named 2024 BAFA Youth Coach of the Year. He is focused on using technology—from AI to Clipchamp—to gain a practical edge.