The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/The Business of Cybersecurity
The Business of Cybersecurity artwork

Why Digital Identity Is Broken And How Ditto Plans To Fix It

The Business of Cybersecurity · 2026-04-17 · 35 min

0:00--:--

Key moments - from our scoring

Substance score

70 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality15 / 20
Guest Caliber16 / 20
Specificity & Evidence12 / 20
Conversational Craft13 / 20

The episode explores why the foundational assumption of digital identity - that more data enables better decisions - is flawed and unsustainable. Gonzalo Alonso draws on experience at Google and Microsoft to trace identity's evolution from access management to convenience at scale, now arriving at trust infrastructure. He explains how the European Digital Identity Wallet and EIDAS regulations mandate user-controlled, cryptographically signed credentials rather than organizational data hoarding. This shift replaces weak signals (passwords, tokens vulnerable to phishing) with verifiable proofs bound to real users and devices. For businesses, this means abandoning the fantasy of owning customer identity; for individuals, it means proving claims without exposing personal data. Alonso emphasizes real-world applications like Spain's mobile digital licenses and describes how interoperable attestations could accelerate financial inclusion and cross-border mobility. The episode addresses risks including device security as critical infrastructure, recovery mechanisms, and system fragmentation - but frames these as solvable challenges compared to the broken legacy model.

Key takeaways

  • →Digital identity's core problem is the assumption that collecting more personal data enables better decisions, creating distrust across users, governments, and organizations.
  • →The European Digital Identity Wallet shifts from data ownership to user-controlled cryptographic proof, allowing individuals to selectively share attestations without exposing personal information.
  • →Cryptographically signed, device-bound credentials with phishing-resistant architecture replace vulnerable tokens and passwords as the foundation of identity infrastructure.
  • →Organizations built on owning customer identity data must fundamentally restructure their business models, particularly banks relying on data assets and open banking frameworks.
  • →The convergence of 27 EU member states mandating decentralized identity creates unprecedented multi-national scale with pre-approved standards, increasing the model's chances of global adoption.

In this episode

  1. 1The Broken Architecture of Digital Identity
  2. 2How European Digital Identity Wallets Empower Users
  3. 3The Shift from Data Collection to Cryptographic Proof
  4. 4Evolution of Identity: From Access to Convenience to Trust Infrastructure
  5. 5Business Challenges in a User-Controlled Identity World
  6. 6Real-World Implementation: Spain's Digital Mobile Licenses
  7. 7Risks and Unintended Consequences of the New Model

Mentioned

DittoNordlayerGoogleMicrosoftGonzalo AlonsoEuropean Digital Identity WalletGDPReIDAS

Guests

Gonzalo Alonso

Topics in this episode

Phishing-resistant authenticationGDPRZero-knowledge proofsOpen BankingDigital walletsDecentralized identityDittoEuropean Digital Identity Wallet (EDIW)EIDAS regulationsCryptographic proof

Questions this episode answers

What is wrong with how digital identity works today?

Digital identity is built on the flawed assumption that collecting more personal data about users enables better decisions. This has created a system where organizations claim to own user data, users don't trust any of it, governments fail to protect it, and security breaches leave people one breach away from total compromise.

How does the European Digital Identity Wallet change the user experience?

Instead of handing over personal data to organizations, users carry proof of their identity in a secure wallet and choose what to share with whom. For example, someone relocating from the US to Europe could share cryptographic proof of their identity to authorities before arrival, avoiding six months of bureaucratic limbo.

What is the difference between data and proof in digital identity?

Data is the personal information itself (name, address, date of birth), while proof is a cryptographically signed attestation that you have verified information without exposing the underlying data. You can prove you own a car or have certifications without revealing the detailed information behind those claims.

Why is cryptographic proof more secure than passwords and tokens?

Passwords and tokens walking around the network are vulnerable to interception and phishing attacks. Cryptographic proofs bound to a specific user and device are phishing-resistant by architecture, making them far harder to compromise or impersonate.

What major business challenge does decentralized identity create for banks and financial institutions?

Banks have treated customer identity and data as critical assets; decentralized identity makes it illegal for them to own that role and forces them to shift to open banking models where users control their own identity, potentially representing significant loss of what they considered key business assets.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode contains several substantive ideas about identity architecture, decentralized identity, and the shift from data collection to cryptographic proof. However, it suffers from significant repetition of core concepts (the flawed data-collection model, user control, cryptographic proof) across multiple segments, and includes lengthy tangential discussions (Spain's mobile licenses, personal relocation story) that don't densely pack new operational insights. A B2B operator learns the core framework but must wade through considerable filler.

the assumption has been the more data I have about someone, the more qualified projections I can do about that specific person. I think that is totally wrong.
we're changing from weak signals to cryptographic proof

Originality

15 / 20

The episode articulates a genuinely contrarian position - that digital identity's core problem is architectural, not technological, and that user-owned credentials bound to devices represent a fundamentally different paradigm. The framing of moving from system-trust to proof-trust and the emphasis on recovery as a critical risk are relatively fresh. However, decentralized identity and zero-knowledge proofs are not new concepts, and the guest relies heavily on established regulatory trends (GDPR, eIDAS mandates) rather than novel first-principles reasoning.

Build a new model that makes the existing model obsolete
At this point, I don't think identity technology is the problem. I think the model is the problem.

Guest Caliber

16 / 20

Gonzalo Alonso is a credible operator with substantive experience at scale: Microsoft during the Hotmail era (identity as access), Google during early growth (identity as convenience at scale), and now leading Ditto through European regulatory implementation. He has deep exposure to identity challenges across different organizational contexts and is actively shipping products in a regulated environment. This is practitioner-level expertise, not thought-leadership-only positioning.

at Microsoft...how do we give safer access to everyone?
at Google, it meant convenience...how do we add scale with billions

Specificity & Evidence

12 / 20

The episode provides some concrete examples (Spain's mobile license adoption, moving from US to Europe creating identity limbo, car ownership as proof for credit), but lacks hard data, metrics, timelines, or financial figures. The guest makes claims about regulatory adoption (Canada accepting decentralized identity, 27 EU countries mandating it) without specific dates or implementation details. The conversation remains largely conceptual rather than grounded in numbers or named case studies of actual implementation challenges or wins.

Spain has had an incredible uptake in digital mobile licenses
Canada has already accepted decentralized identity as a model

Conversational Craft

13 / 20

The host asks substantive follow-up questions and demonstrates real curiosity (evolution across Microsoft/Google/Ditto, unintended consequences, business challenges), showing he's done research. However, the host rarely pushes back or challenge claims; he accepts the guest's framing without probing contradictions (e.g., the claim that 'technology isn't the problem' deserves skepticism). The interview reads more as exploration than pressure-tested dialogue. The host also allows long monologues without breaking them up for clarity or follow-up depth.

How has your perspective on identity evolved across these different environments?
what challenges does this create for a business...when they no longer control the identity layer?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

identity43world33trust24data19model18user17digital16real13proof13europe11back10systems10different10ditto9google9infrastructure9

Episode notes

What if the real problem with cybersecurity today is not the threats we see, but the way we prove who we are online? In this episode of the Business of Cybersecurity podcast, I sat down with Gonzalo Alonso, CEO of Ditto, to explore why digital identity has quietly become one of the most important and misunderstood challenges in our digital economy. Drawing on his experience at Microsoft, Google, and now Ditto, Gonzalo shares a perspective that challenges long-held assumptions about how identity works, who owns it, and why the current model is starting to break under pressure from AI, regulation, and evolving user expectations. We unpack what is changing across Europe with initiatives like the European Digital Identity Wallet and what that really means in practice for both consumers and businesses. Gonzalo explains how the shift toward user-controlled identity could reshape everything from onboarding and compliance to fraud prevention and cross-border trust. At the same time, he does not shy away from the complexity this creates for organizations that have historically treated identity data as an asset they control.

Full transcript

35 min

Transcribed and scored by The B2B Podcast Index.

So a big thank you to Nord layer for backing the podcast and supporting the kind of real world cyber security conversations that we need more of because there's someone that records 65 plus interviews a month. I've personally seen a huge increase in browser based attacks over the past year, whether that be phishing, malicious extensions, account takeovers, the list is long and it's all happening where people spend most of their time inside the browser. So Nordlayer's new business browser that's built to address exactly that.

It blocks malicious sites before they load. It limits risky behaviors like uncontrolled downloads or data sharing and gives you visibility into how your team interacts with web apps. And it also helps you stay compliant by controlling access and enforcing policies. without the need to rely on multiple disconnected tools.

So for anyone listening that is thinking seriously about reducing risk in SaaS heavy environments, this feels like a smarter and more focused approach. And you can learn more about it by visiting Nordlayer .com slash browser. Let me know what you think.

But now let me introduce you to today's guest. How many times have you handed over your personal data online today? Maybe done it without even thinking about it. Maybe it was logging into an app, a social media site, signing up for a service, or just ordering a coffee.

We've all been trained to almost accept it. Type in your details, trust the system, move on. But here's the uncomfortable question. What if the entire model that we've built digital identity on?

is fundamentally flawed. Well, today's guest believes this is exactly the case. Joining me all the way from Barcelona is the CEO of a company called Ditto, and they're rethinking digital identity from the ground up. And with leadership experience at Google and Microsoft, he has seen firsthand how identity has evolved from simple access to convenience at scale.

And now to something much bigger. Trust infrastructure. So today we're going to explore why identity is breaking under the weight of modern threats, how European regulation is shifting back to individuals, and why the future of authentication might rely less on passwords and more on mathematics. And yet we'll also get into what this means for businesses who have built their entire models around owning customer data, and why that error.

might be coming to an end faster than many expect. So if you've ever wondered who really owns your digital identity and what happens when that answer changes, you're going to want to stick around for this one. But enough from me. Let me introduce you to my guest now.

Can you tell everyone this thing a little about who you are and what you do? Hi, Neil, and hi to all your audience. Thank you for inviting me here. I'm super excited.

So I'm Gonzalo Alonso. I am the CEO for Ditto and at Ditto we do something that is actually pretty simple to explain but it's really hard to solve and that is one of the things I love about what we do at Ditto. So we focus on the trust of the digital world if you want to have it more abstract. So at Ditto we think that there is one problem that we haven't solved online at all and that's trust.

And until we don't solve that missing layer of the digital economy, that's how I see it, we won't be able to move forward in many, many other stuff. But the simplest example I have is a transaction. I don't think that transaction will be the fuel for things like volumetrics in the future anymore. I see identity as being the fuel for that volumetric transactions in the future.

specifically in identity, which is where we want to create trust in the digital world, we focus on how do you know that person or thing on the other side of the transaction? And how do you trust and prove who that person or even material thing is? And that's the challenge that we have right now to solve. And I think all over the world, this is a challenge that should be in many people's Mine so we in this world where everything becomes more and more remote our job is create trust in the infrastructure so that you can.

Stop trusting other how other people manager data and you can start managing it yourself as a citizen of the world so not a minor thing. As I said, this is something that hasn't been solved yet. So it's one of those challenges that, you know, it's it's tough and we wouldn't have it any other other way. That's exactly what we would like to solve that.

And it's funny you say that, because I would say over the last, what, three to six months, the word that has been transported right into the spotlight, probably because of AI, agentic AI and all these agents out there, is identity. There seems to be setting off a lot of alarm bells right now. And when I was doing a little research on you, you've described digital identity as fundamentally broken. So starting from the top, where exactly is identity failing today and why have passwords, tokens and existing systems struggled to keep up with the modern threats we're seeing now?

It's a great question. And I think identity is fundamentally broken because of its architecture, of its legacy architecture. And let me be more like eating the toe. At the core of identity, we have the wrong assumptions, if you look back in time.

If you look at least back in time to the last 25 years, the assumption has been the more data I have about someone, the more qualified projections I can do about that specific person. I think that is totally wrong. I think that the era where we all go collecting data in this fantastic world, where we think we own it as an organization, we create the flows for it. We create our own definition of what's privacy and our own, in most cases, our own definition.

Of course, governments regulate entities in many cases, but still, there's a lot of movement there for people to... And then fundamentally, this has created a world where people don't trust data anymore. And that inference is hitting directly the core of what we do online. So it's time that we stop asking everyone for personal data.

I think that's crazy. I see governments all over the world failing at keeping that data stored in the right way and managed in the right way, and then finally being secured in the right way. If this is what's broken at its core, how do we turn this around? And it seems we have many promises in a lot of geographies and many ideas on how we could start doing this without making it more complicated and risky for everyone.

Because right now, where we are, is we're all losing, right? So the user doesn't trust anything. The government state that times three. And then we have this ecosystem of private organizations thinking, and this is not only banks by the way, thinking that the data is theirs.

And I think within that fantasy lies the problem of the whole conundrum. It really does and you were talking about the different promises that are being made in different geographies around the world and here in Europe there are initiatives like the European Digital Identity Wallet which we're seeing an almost shift towards giving individuals more control over their data, at least that is the promise. But what does this actually mean in practice for consumers listening and how different will their experience feel just to help them bring it to life?

totally changes them all. So it flips them all around. So what it means for users, which is actually the most important part of the equation, even if we have to forget this sometimes, but it puts users in the middle of the equation, which is the first thing we needed to admit. So this is not about everyone owning as much data.

Or view as they can. This is actually about understanding who you are without exposing you to all of the problems that exist. So specifically in Europe and around UD laws, we're promoting, we're mandating this idea that the instrument to carry around your identity should be a digital wallet. and that this digital wallet, that it's very different from other wallets we've seen.

Most wallets we've seen, their focus is transaction. This wallet specifically, it's focused to keep your personal information secure. So within this wallet, in Europe we're calling it the identity wallet, lies proof of who you are. not that data of who you are, but proof that you have attested to of who you are.

And then you as a user get to choose who do you want to share that data with, depending on how it really empowers your life different. So what we found is just like pushing the systems as a national identity system from somewhere above to everyone else creates a lot of wrinkles in the ecosystem. So many that we haven't been able to move forward with the with this around around the world you know. If we suddenly give integrity to the information and we make it secure and then we put at the user in the steering wheel.

Then suddenly you have this interoperable system that we can start sharing without sharing the information. the personal information of the user for everyone out there that isn't sure knowledge of proof and what i think it's really cool about your knowledge of proof if you go back fifteen years. Fifteen to twenty years we didn't know what to do with that model it's a very sophisticated math model it is and then suddenly we start finding some applications probably fifteen years ago blockchain is born and it creates this backbone for crypto.

Among other other things so listen to this case which is my case right i just moved from america to europe yeah of course. I've been working in america and international companies my own company so i like so i got credit there i've got had little investments there where i meant something. in that part of the world. When you move to Europe, you go back to actually being in a limbo, identity purgatory.

You're not whatever you came from in America anymore. You have to fit in into this new digital societies, and it takes you about six months. One of the most exciting things about decentralized identity and the whole UD proposition is that, you know, In the future in the very near future before even traveling to europe i can choose to share some of my proof. Where the government in the other side of the ocean so they can start looking at that proof and see if they can trust me or not and if they can verify who i am or not.

that would actually save someone like six months of their life from being a living hell to actually becoming a productive citizen for another country really, really fast. And I think that has a huge economical impact and so on. But we also see that while identity fuels transaction, very cool things happen. So, for example, you buy a car.

The moment you buy a car, you cannot test for that car. So you have proof of ownership of something. And that, you know, thinking of inter -parallel priority can help you leverage that asset for other things, which brings credit to a more democratized society. And it brings a constant real -time thermometer of who you are and what you want.

You know, if suddenly in a couple of years, I need more credit from a bank, I can actually show the attestation of my car, which is proof of what I own, which could mean a credit of about the size I would want for my company at that moment. And suddenly, you're leveraging your identity to grow in the financial world with things that we haven't been very effective around the world taking to the mass population. As you can see, what we're doing in Europe really excites me because it also has a lot of backbone, right?

It's got GDPR has gone all over the world. It's now standard and ADAS same. So I envision the mandate of ULIT also to go across the world. And I think this is the actual model that makes the other model just inadequate and old.

And on the flip side of everything we're talking about here, for the business leaders listening who are currently shuffling a little nervously in their chairs, what challenges does this create for a business that when they have to operate in a world where they no longer control the identity layer in the same way, it's going to be a few challenges there too, right? It's going to be a lot of challenges. So first of all, organizations have to face the fact that the way that they've been using identity is never going to come back.

Theoretically as time passes and as we go into the mandate specifically in europe but not only europe canada has already accepted decentralized identity as a model to go and so as companies realize they can't own. Quote unquote the identity of the users and more they will have to shift to the mandates very fast and for you know organizations like banks. This means should totally shifting their model to something they've been avoiding now for years right so we can talk as much as you want us open banking but.

Open banking has not changed my life, or my kid's life, or your life. So we have to start facing the fact that there's something wrong with that model that hasn't become the standard we thought it was going to become in terms of sharing data. So that's a big shift for any kind of organization, especially banks. And in the financial world, this is actually If you don't manage it well, could very well mean loss of assets.

Because these guys were convinced this information was one of their most important assets. So what happens in a world where clearly it's illegal for you to take that role and you empower the user to do it. To say the least, it's going to be an interesting ship. The other thing we're used to is just asking everyone for information.

And this I see, look, it's ridiculous. It goes everywhere from my fitness club to a restaurant, right? And it's way past dangerous. It's chilling at this point.

And users all over the world don't realize that they're probably one line of data away from being totally hacked. The other things that will change severely is how how do we deal with recovery. Go in in the systems we have right now yes if i can recommend that very tough to interoperate on them but it is true that if you lose credentials. Somewhere that you can get them back pretty easy in this new world recovery some type of paradigm where you really need to create the models.

on which you create trust really, really fast again on scenarios like what happens when a user loses or gets stolen their mobile. And that is the simplest of examples, but we can go all the way down to a very tough example. So everything will change and it will... So how I like to put it is we're changing from weak signals to cryptographic proof.

That is 90 % of the living acting producing world right now, which makes it really interesting. And as you said there, we are talking about moving from those weak signals to just trusting systems to relying on cryptographic proofs. Can you tell me a bit more about what that shift looks like in real world terms, especially for organizations? It's very serious about trying to reduce fraud and meet regulatory demands and do things the right way and be a part of this shift rather than resisting the change.

Tell me more about that. It all starts from my point of view. You said it really well, right? We now trust systems.

We need to start trusting cryptography, which means infrastructure becomes something really different as we know it today. And that's also, I get very passionate with this subject. So going from trusting systems to trusting cryptography, it's a big, big change. And to me, How do you start doing this?

Asking different questions about what you're trying to do. So the first question I would ask is, do I trust the system I'm going to have contact with? And there will be systems that you do trust just because of legacy. Many of the systems in the banking ecosystem, we just trust, right?

Swift, whatever, right? And then they will have... to adapt to leaving that trust to the user and how they manage their trust. And that's through cryptography and through safe environment.

So that's interesting. The second question I would have to ask myself is, can this claim, you know, whatever the claim the counterpart is doing, can be proven with something? And that something is cryptography, right? So those are the big two questions you have to ask yourself entering this new World because if you don't realize this you're missing the bigger the bigger point which is because the system.

Online hasn't produced the type of trust we need we need to give it back to the actual. Who owns that and then empower him to do something with it which is where the real economy of satisfaction kicks in. And until we don't have this, it's going to be a right. And then I see a few things happening, right?

So the mandate is very clear. Although I could say that you could have your own flavor of making a few decisions. And then one of the problems we might have if we don't take this seriously is fragmentation. So instead of having this system that we don't trust, but we trust on its proof, then suddenly that proof can go to hell.

So what do we need? The credentials that are digitally signed. That's what it looks like. Those credentials have to be bound to a real user and a real device.

And when I say a real user and a real device, it's like, forget the burners. Forget all the anomalies you can think about in the system. You have to critically just shove them away and leave this. And then authorization that is phishing resistant.

Because right now with tokens and all that stuff walking around is that we found tokens can be intervened. We found all type of non -cryptographic messages can actually be broken and phished. So I think if you ask me what it really looks like, it looks like credentials that are digitally signed and with protocols that are worldwide, and if not worldwide, geographically approved, bound to a real user and a real device. And you know that it has real systems that are anti -feaching by architecture, which is the one thing we don't have right now.

And on a personal note, looking at your career, you've held leadership roles at Google and Microsoft. Now you're leading Ditto. I'm curious. How has your perspective on identity evolved across these different environments?

Because you must have seen an experience so much. Neil, it's a journey. It's been a journey. It's been a real journey.

So this is a tough question because you can argue in the 90s and early 2000s at Microsoft, you know, What was identity about? And I would say at that point in time, it was about access. Hotmail was probably the biggest database around of Lehman. People just there.

And at Microsoft, the conundrum will ask, how do we give safer access to everyone? And that was it. Then I went to Google. And in Google, it took a totally different meaning.

So at Google, identity when I was at Google, which is early Google, it meant scale and convenience with a big underlying inconvenience. Because scale was getting there, but we had to take care of the projections, not of the reality, because of the natural rhythm of how everything was grown. So at Google, it meant convenience. So how do we add a scale with billions, right?

How do we make this convenient for everyone in a world where you will have a suite for, you know, your work sessions and a suite for your personal sessions and so on, so forth. And then addito, it means something else completely, because both Microsoft and Google still have this fantasy of owning identity. That's what I think. Did they explore everything, right?

But what they would love is for this conundrum to sort of like play the way they want it to be played. Of course, these guys are freaking smart. They have the interoperability at some point in the world with data. So they know a lot of things we don't know.

And this thing of playing your own identity sooner or later, I think is going to give them a reality check. Like it gives like reality gives checks to everyone, right? So in Ditto, we think totally different. So identity is not owned by a platform, it's owned by a user, with, as I said before, with the right credentials, the right unit, and the right platform that is doing that.

So my trip from access to convenience to trust infrastructure, has been super interesting, because now it's very clear for me that infrastructure for this new identity in the future will mean something that is owned by the user, that it's managed by the user, and our job is just to provide the user with the way that identity will change its world because he owns it. Simple example, Spain. So, Spain has had an incredible uptake in digital mobile licenses. And everyone's asking like, what do you think?

What's going on there? Nothing's going on there. It works. It's something that a citizen can own, understand.

They can see how it works for them. It's practical. So, why not download a governmental wallet in Spain? fundamental trust with the government.

And why not attest to your license, which is your first proof of who you are. And once we have this in a wallet, and by the way, these attestations are interoperable, which means I can check if I'm qualified and I'm structured enough and have certifications, I can use these attestations also. And suddenly this world that is very siloed, it just became more of a, you know, common ground for certain things. So it has to be provable.

It has to be owned by the individual. It has to be provable anywhere. That's one of the conundrums we have while working at this stuff, right? And yeah, so I've gone through this very naive thinking, I would almost call it Kapchka thinking.

to this very sophisticated and empowering technology vehicle that we're providing to, at least in Europe, to citizens. I'll tell you why this is powerful in Europe, because of the 27 countries mandating upon it. So suddenly you have something we haven't had in the world, which is scale at a multi -nation level with pre -approved facts. This is why I think this one has a special chance to actually make it.

Absolutely. Love it. And if we look ahead, if digital identity is rebuilt around privacy and user control, lots to celebrate there. But rather than move fast and break things, are there any new risks or unintended consequences that we should possibly be thinking about now to ensure we don't create anything else?

Every time we change the model, there's new risk. One of the quotes I log is from Bookminster Fuller. He was a graphic designer back in the 70s, a brilliant man, brilliant mathematician. I'm going to read it because I don't want to misquote him.

He said, you never change things by fighting the existing reality. Build a new model that makes the existing model obsolete. I think that's exactly what we're trying to do. So, while making obsolete the legacy model, of course, we have a lot of risks.

So, I'll name a few. So, device becomes critical infrastructure for the world, not for the guy that's using it, which of course it is, but it's a trust -relating infrastructure that will be on the hands of users. We've never done that. Yeah.

I'm excited about it because probably by not doing what everyone has done is how we're going to find the answer, right? But yeah, I mean, this is the first time that in the identity world, we choose devices as part of the critical infrastructure to deliver identity. And I think that's fascinating. And of course, it will bring new challenges and new risks, right?

One, it will become a high -value target for all of those not that want to steal your information or want to take your identity or whatever. But I think that protecting wallets, in fact, we have technology to do that. Even European identity wallets will be easier. That containing this problem of everyone asking for data and treating it differently because this is how we treat it or whatever.

And then I already said it, but it... I think the biggest risk is getting recovery right. Because once you've messed up with a user, it'll be tough for him to believe in the system again. And then if he takes six months recovering his identity, we've lost purpose of what we did, you know, originally.

So recovery is, I think it's going to be a very important part. So for Ditto, or at least how I see it is, how do we balance the user controlling identity, the strong security that has to be behind it, and then the global standards that make it interoperable. I think those are the main risks we should be very aware about and then just focus on them. They're very solvable.

So this is not a technology problem. People sort of feel uncomfortable when I say it. At this point, I don't think In -identity technology is the problem. I think the model is the problem.

And we're not being successful at tackling the problem itself because we have chosen to follow the same model for 10 or 15 years. And as you know, I think that legacy model is inherently broken. So whatever happens from here till we get it right, it only gets worse. You can throw millions and millions of dollars at cryptography at this point.

If you don't change the model, I don't think it'll have a lasting effect at all. Wow, I think that's a powerful moment to end on. So for anyone listening that are inspired by your passion for this topic, wanting to learn more about Ditto, connect with you or your team. Will you like me to point everyone before I let you go?

So you i mean for everyone they want to know more about you should go to a webpage which is dito dot id you can find me gonzalo alonso seo dito linkedin and i will have a dito a page at linkedin and yeah we're always glad to listen to you outside get opinions feedback even a debate going i think this is this is when we try to get. better identity by understanding not just the technological things that make it so powerful but also the model itself that has to travel with the modern data sheets.

Well, I will have links to everything. I'd urge everyone listening to go check out, learn more about what you're doing. And this mission that you're on here of building the next phase of digital identity with cryptographic principles, but take the tech away for a moment. It's consumer privacy at the very core.

And I think that's something we can all celebrate, I think. So a big thank you for sharing your story today. Really appreciate you. Thank you, Neil.

It's been great. And thank you to all your audience for listening to us. There was a line that Gonzalo shared in this conversation that particularly resonated with me and that is we're moving from trusting systems to trusting proof and when you sit with that for a moment it changes how you look at everything from logging into your bank to proving who you are online to how businesses build relationships with their customers and it's this shift that feels subtle on the surface but underneath it rewrites the rules completely.

So for consumers there's real promise here. More control, more privacy and potentially a world where you decide what to share and when. And for businesses I think there's a tougher conversation. Letting go of control over identity actually means rethinking long -standing models and for some that might feel like losing one of their most valuable assets.

And then there's the reality that every new model brings new risks. Devices become critical infrastructure, wallets become high -value targets and recovery becomes just as important as security itself. And if we look at what happened with cookies on websites, it's not actually protected us. It just means you have to click about three or four times just to scroll down a website.

So this isn't just a simple story of progress. I think it's a story of trade -offs, opportunity. and a fundamental rethink of how trust works in the digital world. But I don't hear your take on this.

Are we ready to take back control of our digital identities? Or have we just become too comfortable letting somebody else manage it for us? As always techtalksnetwork .com, pop over there, let me know your thoughts, have a little visit of the site.

and click on some of the links in the show notes and let me know your thoughts. But that is it for today so thank you for listening as always and I'll speak to you again very soon. Bye for now.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Emre Kazim (Holistic AI): Why AI Governance is Life CybersecurityThe Road to Accountable AI · on GDPR90 / 100
  • Enterprise Software Buyers Now Demand a Vendor AI Training Data Provenance AuditB2B SaaS Talks with Fexingo · on GDPR80 / 100
  • Inverted Podcast #24: What’s Happening in Identity?The Inverted Podcast · on Phishing-resistant authentication80 / 100
  • Social Media Screening For Safer Hiring Decisions with Ben MonesHRchat Podcast · on GDPR78 / 100
  • #431 - Tectonic Shifts in Identity Security with Martin KuppingerIdentity at the Center · on Decentralized identity77 / 100
  • Ex-lawyer turned founder on reimagining hotel direct booking engine ft. Frédéric Robles of NamastayMatt Talks Hospitality: Real conversations for innovative hoteliers · on Digital wallets77 / 100

More from The Business of Cybersecurity

All episodes →
  • Closing the AI Vulnerability Remediation Gap With Cobalt74 / 100
  • Mimecast CISO On Why AI Has Become A Cybersecurity Risk60 / 100
  • Orange Cyberdefense On The New FCA Cyber Reporting Rules76 / 100
  • Deepfakes, AI Agents, and the Collapse of Traditional Identity Security66 / 100
  • When Identity Becomes The Front Line Of Cybersecurity71 / 100
All The Business of Cybersecurity episodes →