Microsoft Security Chief Issues Call to Arms to Protect Metaverse
The metaverse, a concept that promises to let users live, work and play within interconnected virtual worlds, will present some unique and more serious security challenges for technology and cybersecurity companies.
March 28, 2022 at 11:16 AM
3 minute read
Microsoft Corp.'s new security chief Charlie Bell issued a call to arms to build protection from hackers and criminals in the emerging metaverse from the start of the new technology.
"There's going to be a lot of innovation and there will be a lot of struggling to figure out what has to be done," Bell said in an interview. "But I think because of the speed, there will be fast innovation on the security side."
The metaverse, a concept that promises to let users live, work and play within interconnected virtual worlds, will present some unique and more serious security challenges for technology and cybersecurity companies. As an example, hackers may be able to make avatars that look like a user's trusted contacts, a twist on the traditional email phishing scheme that will be hard for users to resist, he said. The nature of the metaverse, which offers the possibility of less centralized control of content and users, also is a challenge for those trying to protect customers.
"Picture what phishing could look like in the metaverse — it won't be a fake e-mail from your bank," wrote Bell, Microsoft's executive vice president, security, compliance, identity, and management, in a blog posted Monday on Microsoft's web site. "It could be an avatar of a teller in a virtual bank lobby asking for your information. It could be an impersonation of your CEO inviting you to a meeting in a malicious virtual conference room."
It's critical for companies operating in the metaverse, which include Microsoft and Meta Platforms Inc., formerly known as Facebook, to design their new products with security and safety built in from the start, rather than bolted on later, after issues crop up. With applications likely to run the gamut from games to entertainment to corporate meetings, developers who are building the software and people using it will have to figure out how to police the metaverse, keeping out hackers, abuse, harassment and inappropriate content. The software companies will need to work together on interoperability of identities, so a user can show they are who they say they are across multiple metaverses, and on other security tools and steps, Bell wrote. Failing to plan ahead may doom the new technology.
"We have one chance at the start of this era to establish specific, core security principles that foster trust and peace of mind for metaverse experiences. If we miss this opportunity, we'll needlessly deter the adoption of technologies with great potential for improving accessibility, collaboration, and business," said Bell, who, until he joined Microsoft in 2021, worked many years for Andy Jassy at Amazon.com Inc.'s cloud unit.
With many metaverse platforms and many apps built on top of them, companies will need to work together to secure the potential gaps and seams between different systems. Tools will need to be designed such as multifactor authentication and customized ways to login without passwords. Bell also suggested something similar to recent advances in cloud security in which companies offer a single program to manage and watch security and access to multiple cloud programs from different vendors.
Still the decentralized nature of the metaverse can also be an advantage if it means multiple companies bring their security expertise to bear in things like verifying identities and providing transparent bug reports, he said.
Dina Bass reports for Bloomberg News.
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllFlorida’s Civil Procedure Rules: Attorneys Foresee More Settlements Amid Time Challenges
3 minute readHolland & Knight Promotes 42 Lawyers to Partner, Prioritizing Corporate Practices
3 minute readData Breach Lawsuit Against Byte Federal Among 1,500 Targeting Companies in 2024
4 minute readTrending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250