Cointime

Download App
iOS & Android

Protecting Privacy in the Metaverse

Validated Individual Expert
Image generated by Rosenberg using Midjourney

Virtual and augmented reality are deeply humanizing technologies, empowering users to experience digital content in the most natural form possible. At the same time, there are major privacy concerns, as metaverse platforms could easily track and profile users at levels that go far beyond any current consumer technologies.

So what can we do to protect our privacy in the metaverse?

The image below shows me standing in a “Virtual Escape Room” created by researchers at U.C. Berkeley’s Center for Responsible Decentralized Intelligence. The simulated world requires me to complete a series of tasks, each one unlocking a door. My goal is to move from virtual room to virtual room by solving puzzles that involve creative thinking, memory skills, and physical movements, all naturally integrated into the experience.

Louis Rosenberg inside a Virtual Escape Room created by researchers at UC Berkeley (2022)

I am proud to say I made it out of the virtual labyrinth and back to reality. Of course, this was created by a research lab, so you might expect the experience was more than it seems. And you’d be right — it was designed to demonstrate the significant privacy concerns in the metaverse. It turns out, while I was solving the puzzles, moving from room to room, the researchers were using my actions and reactions to determine a wide range of information about me. I’m talking about deeply personal data that any third party could have ascertained from my participation in a simple virtual application.

As someone who’s been involved in virtual and augmented reality for decades, and who’s been warning about the hidden dangers for years, you’d think the data collected would have not surprised me. But you’d be wrong. It’s one thing to warn about the risks in the abstract — it’s something else to experience the privacy issues firsthand. It was quite shocking, actually.

That said, let’s get into the personal data they were able to glean from my short experience in the escape room. First, they were able to triangulate my location. As described in a recent paper about this research, metaverse applications generally ping multiple servers which enabled the researchers to quickly predict my location using a process called multilateration. Even if I had been using a VPN to hide my IP address, this technique would still have found where I was. This isn’t shocking, as most people expect their location is known when they connect online, but it is a privacy concern none the less.

Going deeper, the researchers were able to use my interactions in the escape room to predict my height, the length of my arms (wingspan), my handedness, my age, my gender, and basic parameters about my physical fitness level, including how low I could crouch down and how quickly I could react to stimuli. They were also able to determine my visual acuity, whether or not I was colorblind, the size of the room that I was interacting from, and basic assessments about my cognitive acuity. The researchers could have even predicted whether I had certain disabilities.

It’s important to point out that the researchers used standard hardware and software to implement this series of tests, emulating the capabilities that a typical application developer could employ when building a virtual experience in the metaverse. It’s also important to point out that consumers currently have no way to defend against this — there is no “privacy mode” in the metaverse that conceals this information and protects the user against this type of evaluation.

Well, there wasn’t any protection until the Berkeley researchers began building one — a software tool they call “MetaGuard” that can be installed on standard VR systems. As described in a recent paper from lead researchers Vivek Nair and Gonzalo Garrido of U.C. Berkeley, the tool can mask many of the parameters that were used to profile my physical characteristics in the metaverse. It works by cleverly injecting randomized offsets into the data-stream, hiding physical parameters such as my height, wingspan, and physical mobility, which otherwise could be used to predict age, gender, and health characteristics.

MetaGuard Image from Nair and Garrido

The free software tool also enables users to mask their handedness, the frequency range of their voice, their physical fitness level and conceal their geospatial location by disrupting triangulation techniques. Of course, MetaGuard is just a first step in helping users protect their privacy in immersive worlds, but it’s an important demonstration, showing that consumer-level defenses could easily be deployed.

At the same time, policymakers should consider protecting basic Immersive Rights for users around the globe, guarding against invasive tracking and profiling. For example, Meta recently announced that their next VR headset will include face and eye tracking. While these new capabilities are likely to unlock very useful features in the metaverse, for example enabling avatars to express more realistic facial expressions, the same data could also be used to track and profile user emotions.

This could enable platforms to build predictive models that anticipate how individual users will react to a wide range of circumstances, enabling adaptive advertisements that are optimized for persuasion. Such ads in the metaverse has been theoretical, but just this month ROBLOX (which boasts over 50 million daily active users, nearly all of them kids) announced they will begin “immersive advertising” in 2023. If a company focused on kids is headed in this direction, we can guess that most major platforms will follow unless policymakers put restrictions in place.

Without regulation, we need to worry that immersive advertising could cross the line from marketing to manipulation. This could be used to push products or services through predatory means, or worse it could drive misinformation more efficiently than any current technologies. As I discussed with POLITICO last week, an unregulated metaverse could become the most dangerous tool of persuasion humanity has ever created.

Don’t get me wrong — I firmly believe the metaverse has the potential to be a very positive technology for humanity. That’s why I have been pushing for immersive worlds for over 30 years. At the same time, the extensive data collected by virtual and augmented platforms is a major concern and requires a wide range of solutions, from protective tools like MetaGuard to thoughtful and meaningful metaverse policy and regulation.

— Note: this article originally appeared in VentureBeat.

Comments

All Comments

Recommended for you

  • Trump: Iran Does Not Want to Close the Strait of Hormuz, They Want It Open

    On April 22, U.S. President Trump stated that Iran does not want to close the Strait of Hormuz; they want the strait to remain open so they can earn $500 million daily (thus, if they close it, they would lose this money). The reason Iran claims they want to close the strait is that I have completely blocked (closed) it, so they just want to 'save face.' (Jinshi)

  • Iran Agrees to Suspend Military Combat, But War Is Not Over

    On April 22, local time, in response to Trump's statement about extending the ceasefire, Iranian state television reported that Iran has emerged as the victor on the battlefield. Controlling the Strait of Hormuz is a highly valuable bargaining chip that Iran has gained in this war. Iran agrees to a suspension of military combat, but the war is not over. Additionally, Iranian state television emphasized that Iran must remain vigilant against any insinuations that it must participate in negotiations, or else the enemy will attack Iran. Even if maritime blockades are lifted, Iran's participation in negotiations must be conditional on not raising any issues that infringe upon Iran's independence and dignity, with the primary concerns being Iran's defense and missile capabilities as well as its nuclear capabilities and technology. (CCTV)

  • Kalshi and Polymarket to Offer Perpetual Futures Trading

    On April 22, following competitor Kalshi's plans to offer cryptocurrency perpetual futures trading, Polymarket has also begun to expand its perpetual futures trading business.

  • Trump Announces Extension of Ceasefire with Iran

    On April 22, U.S. President Trump posted on 'Truth Social' on the afternoon of the 21st, stating that at the request of the Chief of Staff of the Pakistan Army and the Prime Minister, the U.S. will pause military strikes against Iran and extend the ceasefire period. He also requested that Iran first propose a unified negotiation plan. During this period, the U.S. military will continue to enforce a maritime blockade against Iran while maintaining military readiness. He stated that the ceasefire will last until Iran submits a proposal and negotiations are completed, 'regardless of the outcome.' (CCTV International News)

  • BTC Falls Below $75,000

    Market data shows that BTC has fallen below $75,000, currently priced at $74,894.74, with a 24-hour decline of 1.78%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Fed Chair Nominee Waller: Independence Depends on the Fed Itself

    Fed Chair nominee Waller: I will be independent of Trump's opinions. Trump tends to call for the FOMC to cut interest rates. Independence depends on the Fed itself.

  • Digital Bank Revolut's IPO Valuation Could Reach $200 Billion

    The Financial Times reported, citing anonymous investor sources, that the UK digital bank Revolut plans to seek a valuation of $150 billion to $200 billion in its upcoming IPO, a significant increase from its previous valuation of $75 billion. The company's CEO, Nik Storonsky, also revealed that Revolut is preparing for a new round of secondary share sales in the second half of 2026, with a valuation potentially exceeding $100 billion.

  • ETH Falls Below $2300

    Market data shows that ETH has fallen below $2300, currently priced at $2299.92, with a 24-hour decline of 0.38%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Trump: Disappointed if New Fed Chair Does Not Cut Interest Rates

    On April 21, U.S. President Trump stated: If the new Federal Reserve Chair does not cut interest rates, I will be disappointed.

  • Chairman of the Joint Chiefs of Staff Milley States Readiness to Resume Operations

    On April 21, Chairman of the Joint Chiefs of Staff Mark Milley stated that the U.S. is ready to resume operations and can act against Iran at any time. (Axios)