2022-11-11 QuSoft CWI Breakthrough Prize Seminar Bennett, Brassard, Deutsch, Shor

YouTube

Duration: 02:49:09

Transcript

Harry Buhrman

00:00:00 - 00:00:53

Welcome everyone to this special edition of the CWI University of Amsterdam QuSoft seminar. And it’s a great honor to have you all here. And it’s an even greater honor to have Gilles Brassard and Charlie Bennett here, two of the four winners of the Breakthrough Prize in Physics. I will say a little bit more about that. But first I want to give the floor to the director of CWI, Ton de Kok.

Ton de Kok

00:00:53 - 00:04:57

Good afternoon. I first would like to thank Harry for making this possible, this very special event of University of Amsterdam CWI QuSoft. Also on my behalf, welcome to this Turing Auditorium. And also welcome to all present online at the Dutch National Research Institute on Mathematics and Computer Science, CWI. And in particular, again, a warm welcome to Gilles Brassard and Charles Bennett, who received this prestigious prize of three million together with David Deutsch and Peter Shor. You and the other two recipients pioneered the field of quantum computing long before anyone had a glimpse of its promise as we are witnessing it today. Quantum computing has become a field in which the Dutch government is willing to invest about 700 million euros over seven years in a so-called quantum delta program. Development of the quantum computers with ever more qubits, research on quantum algorithms that yield deeper insights into the quantum advantage and thereby of potential applications go hand in hand here and worldwide. And CWI contributes to these developments together with the University of Amsterdam in QuSoft, which was established in 2015 by Harry and Karo-Jan Schoutens. This is a second really extraordinary event this year at CWI. As early April, we had the honor to welcome here two recipients of the Abel Prize 2021, the Nobel Prize in Mathematics, Avi Wigderson and Laszlo Lovasz. And today we are honored with the two of you in our midst. Pioneering a field is the craft of the extraordinary talented, those that see phenomena before others do, that make others see them. And once that happens, the field develops and possibly explodes, eventually delivering benefits to science and society. Such pioneering is seldom, if at all, the result of deliberate policy by people analyzing the problems of today with the perspectives of today and the tools of today. Most people seek certainty and consider exploring avenues with uncertain outcomes, requiring deep investments of time, not very tempting. At CWI, over the 76 years of our existence, a culture has grown that attracts people, researchers that do seek uncertainty and are willing to invest 25 years in quantum computing. Neuromorphic computing, new databases and analytics, further deepening our understanding of optimization and new robust statistics that doesn’t lie. And we believe this culture is quintessential to contribute to the long-term high quality of mathematics and computer science in the Netherlands, and thereby to the wealth and welfare in the Netherlands and globally. We at CWI are determined to maintain this culture while investing our time to team up with researchers from our communities, both nationally and internationally as we are doing today. I happen to know that Gilles Brassard worked at CWI in the 80s, no doubt contributing to this culture of exploration and curiosity. And we are thankful that you became a regular visitor to CWI ever since. And we are thankful to both of you that you are willing to share your thoughts and ideas with us through your presentations.

Ton de Kok

00:04:57 - 00:05:15

I know the audience of today is open and eager to learn. I would like to give the floor to Harry Buhrman, who will introduce David Bennett and Gilles Brassard to us. I wish all of us an afternoon that we will never forget. Thank you.

Harry Buhrman

00:05:15 - 00:08:34

Yes, so indeed, again, welcome to Charlie and Gilles. And actually, this is just an ordinary QuSoft seminar that we have had since 2015, almost weekly. And I’m so very happy that we’re going strong and today even extra strong. So that’s fantastic. And indeed, you two won this prestigious prize and not only prestigious, but also a lucrative prize, as was alluded to by Tom. So and that’s actually not the first prize. You have had a bunch of other prizes and there’s a long list. And I was looking it up and I was almost overwhelmed by all the prizes that you had. But interestingly enough, you also had a bunch of prizes together, the three of you or the two of you. For example, the Foundation Frontiers of Knowledge Award with Bennett and Shor and Brassard. 2019, the Micius Quantum Prize together with Charlie. And not to forget the very important Wolf Prize also together with Charlie, sort of the first or the step towards the Nobel Prize. I’m waiting for that one, but it’s not yet on the list, but I’m sure it will come. You both are pioneers of the field. Indeed, as Tom alluded to at a time, I mean, when this was completely unexplored territory. And actually later on today, I want to ask you both how on earth did you wander into this field? But that’s for later. But when you did, you did fantastic things. One of the fantastic things you did was to develop quantum cryptography and the well-known BB84 protocol, all before Shor came to actually show that that was needed. And also, you are both on the teleportation paper. And I witnessed Charlie teleport a little bit earlier today into Amsterdam, which is also a milestone and a fantastic result in the field. I wrote down here entanglement distillation, quantum entanglement and communication is something that Gilles has been interested in very much. And I had the fortune of being able to talk to him about that later, Gilles. And now I’m focusing more on Gilles. And later on, I will say something more about Charlie, who is still vividly working, vehemently working on his talk. So that should be great. So later on, Gilles, you started to work on the foundations of quantum mechanics and later interpretations, but also deriving quantum mechanics from computer science principles, because you are a computer scientist at heart. And also not to forget the development of quantum algorithms. You have been very instrumental in that. So what can I say? Not much more. And without further ado, I want to give the floor to you. Looking forward.

Gilles Brassard

00:08:44 - 00:12:59

Well, thank you, Tony and Harry, for the nice introduction and for the invitation to come and give this talk. Although it’s sort of very unfair that Charlie can work on his talk during mine and I cannot work on my talk during his. So without further ado, here I am with my talk. This talk, which is only loosely connected with quantum information, but not entirely disconnected. And it’s on a topic that is somewhat surprising. Namely, do we live inside a computer simulation? What’s the probability? And if we do, then what can we do about it? Essentially. Now, you may notice that this is wrong. It’s on purpose because the very first time I gave this talk, I prepared it for QuSoft about a year and a half ago. And of course, in those days, 2021, that was on Zoom. Right. So here you can see, yo. Yo. And that’s me proudly wearing my QuSoft t-shirt. And you have Peter there. And this is my co-author, Alexandre Bibeau. Some of my best students, Charles, Vedat, my wife, my brother. So all sorts of people were there at this Zoom version. But it’s so much nicer, so much more fun to give it live. So I decided to give it again to you today. So some of you have heard the earlier version. It has been improved since because I gave it several other times since the first time. And so there we are. So that’s the real title. Same title, of course, but the real affiliation and the real, because I’m a direct chair in the moment. I proudly show QuSoft as affiliation when I give talks these days. All right. So this talk is based on a paper that I published with my co-author, student, Alexandre, which appeared in Proceedings of the Royal Society. Yeah. Last year. So it’s fairly recent. When I gave the talk at QuSoft, it had just come out. Last time I gave it. And I’d like to start with sharing with you a very funny comment by the referee of that paper in the proceedings. Or else, the editor told me that, all right, we’d like you to revise the paper as usual. But it looks like it’s going to be accepted. And here are the referee reports. And one report, I still laugh when I think of it, said this. Comment. If the following is, if the paper is rejected, it should not be because it’s too crazy or science fiction. Maybe you will find other reasons why not this one to reject it. So you might. When we talk about the simulation hypothesis, the first that comes to most people’s mind is the matrix. So this is Morpheus offering Neo to choose between the red pill and the blue pill. If Neo takes the blue pill, he will just wake up in his dream life and will be happy ever after. And if he takes the red pill, he will wake up in the real world. And it’s going to be very painful. Of course, he takes the red pill, wakes up like this. And then he finds out that there are pods all over the place. Pods and pods and pods. But each pod, each little light here is a pod that contains a human being enslaved by the machines in that movie.

Gilles Brassard

00:12:59 - 00:17:05

Now, the reason why I’m showing this is that, well, that’s not what we’re talking about. Again, the first thing that comes to mind when I talk about the simulation hypothesis is that movie. But it is not what I’m talking about. There is a big difference between the matrix and my discourse, which is that in the matrix, humans really exist. They’re just enslaved. And false memories and false whatever is forced upon their brains. But they are there physically in their pods. What I’m talking about is really simulations where there is no humans whatsoever. It’s all happening inside a computer. So it’s really quite different. Less evil in a sense. Oh, thank you. And what I’m talking about is much more in line with an earlier novel, earlier than The Matrix, by Daniel Galouye called Simulacron-3. If you have not read this, I highly recommend it. In that novel, the main character notices that some things just don’t look right, such as roads that disappear. And he figures out somehow, he figures out the reason is that he, the main character, is living inside the simulation. And that something is going wrong with the simulation. But the reason why this is such a good novel is that this character in the simulation is in charge of building a computer that will do a simulation, that will simulate humans. So it’s a recursive type of simulation. And I won’t say more about the novel if you want to read it. I don’t want to give you the punch. But this notion of recursive simulation in that novel will be directly related to my talk. Now, this being said, I’ll try to take this picture. So this being said, published in 64. And all right. So this is supposed to be a science talk. We’re in a science park, after all. Let’s move on to the real scientific talk, if it can be considered being that. This is mostly serious, actually. Really, really, really. And to prove it, I’m going to give the floor to the richest man in the world. So Elon Musk, well, you all know him from Tesla and SpaceX and nowadays Twitter. But Elon Musk also started and owned all sorts of other companies, a boring company, by the way. It’s not something that’s boring because it’s not interesting. It’s boring holes to build the hyperloop, the hyper whatever, whatever, to do San Francisco and Los Angeles in half an hour or something by train underground. Of course, that’s not what I’m talking about. The point is that Musk is convinced, or at least was, maybe changed his mind. I didn’t talk to him recently. But Musk is convinced, or was, that we do actually live in a simulation. And at the Code Conference in 2015, I think 16, he said this. There’s a very, very, I didn’t include in my talk listening to his video. But I highly recommend that you do because it’s so much fun to hear Musk explaining why he believes that we live in a simulation. But his bottom line is that the odds we’re in base reality is one in billions. So maybe we live in base reality.

Gilles Brassard

00:17:05 - 00:21:19

Maybe we’re not a simulation. But it’s very unlikely, according to Musk. And I will tell you his argument, or rather I will tell you the argument of Nick Bostrom, who came before him and probably gave Musk the idea. Bostrom being a real scientist. Musk is more like an engineer and very great. So he said that at a Code Conference 2016. In fact, the argument of Musk in this video, go on YouTube and really find it. It’s worth it. So what he used in this conference is that we, as human beings in our civilization, if you can call it that, we are very close to being able to be indistinguishable from reality. It was from reality, like virtual reality. But it would be for the characters inside the game, they will, for them, living inside the game will be indistinguishable from living in base reality. So there will be also a large number of virtual beings who will think that they’re real, just as we do. And you will not see the difference, because the simulation will be indistinguishable from reality for them as well. So all of these people, if you can call it that, all of these simulated beings, in a great number, will believe that they are real. And we can imagine, and it’s been hard to imagine, as we progress in this world, as we progress, at some point, there will be far many more simulated beings in games all over the place than real people. So if we’re typical, we’re more likely to be one of them than one of us, because there are more of them than us. That’s the argument. And the only way out that Musk finds, the only way out of this reasoning, the only reason why this would not happen is if we don’t actually manage to design simulations that are indistinguishable from reality, but completely indistinguishable. We’re not there yet. So the only way that this reasoning would be false is if we do not succeed at creating simulations indistinguishable from reality. And the only reason why we would not succeed is if we self-destruct. So from Musk’s point of view, the only way out of us living a simulation is to self-destruct. Ha. I’m paraphrasing. But this is a real quote coming up. So either we’re going to create simulations that are indistinguishable from reality, or simulation will cease to exist. Those are the only two options. I’m really quoting his words from the video. Now, whether you buy this or not is your choice. But let’s move on now to real science. Nick Bostrom wrote a real scientific paper on these ideas in which he concludes that we are currently living a simulation. This is out of context. He doesn’t really say that. But under some conditions, unless we are whatever. But the purpose of the paper is to sort of give various scenarios, one of which is that we live in a simulation, which, according to Bostrom, is somewhat reasonable. But the argument is essentially the one I gave you.

Gilles Brassard

00:21:19 - 00:25:55

OK, now let me give you the argument somewhat more specifically, more seriously, with numbers, not just hand waving in words. So in order to make this argument more formal, let me introduce what Seth Lloyd called the ultimate computer, ultimate laptop. So Seth Lloyd studied what is the computational power of matter, how much operations per second can matter do if properly used, what’s the ultimate limit of computation of matter. And his conclusion is that the ultimate limit of computation is that the ultimate laptop would look like this. And so the ultimate laptop looks like a small piece of a big bang. He says that because it would run at about 1 billion degrees. So it’s not so easy to manipulate. But that’s OK. This is a theory paper. But the point is this. The point is that it would be able to do about 5 times 10 to the 50 logical operations per second, somewhat more than we can do today. That’s for one kilogram of matter. That’s a one kilogram ultimate laptop would be able to do up to 10 to the 50 operations per second. He doesn’t mean that it’s possible to get there. His point is that you cannot do any better. But there is no reason. There is no physical reason to believe that we cannot reach that level. And there’s no reason either to do that with quantum operations per second. And it’s important for my talk, for us at Quantum Talk. So we can go up to 10 to the 50 quantum operations a ultimate laptop. Very good. That’s right. That’s a one kilogram. So let’s call that the computing density of matter. One kilogram of matter can perform up to 5 times 10 to the 50 operations per second. Very good. Let’s keep that in mind. The computing density of matter. Let’s compare that for the human brains. Well, the brain is not nearly as efficient. It weighs more than one kilogram, about 1.4 kilograms on average. And it can go bad. According to best we can see, a human brain can perform up to about 10 to the 16 operations per second. That’s not bad at all, but much less than 10 to the 50. So that now we can do the ratio between the two. And if you divide the power of the brain by, sorry. So the density of the brain, which is its power over its mass, is about 10 to the 50 operations per second per kilo. And if we divide mbra, which is the density, which is. So if we divide dmath by dbra, then we get how many brains can be simulated with the same amount of matter in principle. It’s about 10 to the 35. So in other words, in a 1.4 kilo piece of matter, one could simulate up to 10 to the 35 brains. So now you see I’m getting to the argument that we can have so many simulated beings that there’s no chance that we’re not simulated. I’m not saying that, but that’s the idea. Very good. All right, now I’m going to introduce a lot of variables. Bear with me for a minute or two. By Civ, what I mean is that it’s a civilization that is capable of harnessing a substantial proportion of the computing power of matter.

Gilles Brassard

00:25:55 - 00:30:18

Not the full 10 to the 50 per second, but a sizable fraction, maybe 1 billionth of it, maybe 10 to the minus 12 of it, but much more than we can do today. So we’re going to see that civilization, a civilization that reaches Civ level when it’s capable of doing that. And again, the only reason we could not reach this level is if we self-destruct, because we’re on the path of doing that. OK, so remember that the computing density of matter is 10 to the 50 per second per kilo. Now let’s give to each citizen in a Civ level civilization, let’s give to each citizen some amount of matter that they can use to compute. And by amuse, the equivalent mass that each citizen is given. By equivalent mass, I mean the mass that if harnessed completely at 10 to the 50 per second would give them their computing power. In other words, if in fact their computing efficiency is a billion times smaller, then they will need a billion grams to have the computing efficiency of one gram. So that’s the equivalent mass that each citizen is given. And therefore, each citizen has a computing power, which is amuse times the mass. The equivalent mass that he has, and the computing density of matter by definition. All right, I don’t expect you to remember all these things. That’s why I keep them on the same board. Now, our cal is the average number of brains that each Civ individual can simulate, which is given by its computing power divided by the computing power of our brain. So we just divide one by the other, and you get the average number of brains that each individual at Civ level can simulate. For example, if each individual is only allowed to use one nanogram of equivalent matter, meaning that would be one kilogram if the computing efficiency is one billion, but if we give one nanogram of equivalent mass for computing to each Civ individual, well, then the number, this awful ratio, the number of brains that each individual can simulate is 10 to the 22. That’s a whole lot of brains. Each real individual can simulate at a Civ level, can simulate 10 to the 22. Don’t ask me why it’s consciousness. All right, now, what’s the fraction of people in the history of civilization that reach Civ level? I don’t mean on Earth. I mean in the universe. So in the universe, consider all individuals of all sorts of aliens, whatever, including us. And perhaps for the billions of, no, what? Thousands, maybe millions of years, they live miserably not being Civ level. But then they become at Civ level, and now they’re capable of doing these simulations. So what this parameter here, F civ, is is the proportion across the entire history of that civilization was the proportion of people who reached Civ level compared to the complete number of people. If it’s a bit like this, the number of people living today is not very much less than the number of people who lived from the first human. So this could be sizable, but it could be small.

Gilles Brassard

00:30:18 - 00:34:41

It doesn’t really matter what’s coming. All right, and now, F ded is a fraction of computing power that is used to simulate consciousness, because people don’t have to. Of course, you have all this computing power. You could use it to do all sorts of boring things. There’s no reason you should use all your computing power to simulate other people. So F ded is the proportion of, F is for fraction. So it’s the proportion of your computing power. The average Civ level person or being was the average of its computing power that’s going to be used for the purpose of simulating consciousness. OK. And this number of real individuals, base reality, what Musk called base reality, the number of people in the real world. Very good. And number of sentient beings are simulated. So what we’re after is a ratio between nsim and nreal, or between nsim and nreal plus nsim. This ratio will give us an idea if maybe we are ourselves in a simulation. So these two numbers, number of real people, number of simulated people are key. OK. And therefore, well, so what’s the number of simulated being? If you’ve followed me so far, you multiply the number of real people by the fraction of real people. This is not just at the moment, but throughout history. So you multiply the number of people that have existed throughout history by the fraction that reached Civ level. And that gives you the number of civilized people. And each civilized people has an R-cal amount of computing power, as I spoiled. But we only use an F-ded fraction of it to simulate people. So that gives you the number of simulated beings that each individual, that number of simulated being in the universe. I got it wrong. R-cal is not the computing power. R-cal is how many brains that person can simulate. But we only simulate an F-ded fraction of it because something else with its computing power. All right, so this is an estimate on number of simulated people in the universe as a function of how many real people there are. Good. And now we get to the fraction of simulated people. The fraction of simulated people is how many there are over how many people total, where total includes simulated and real. So there are n real people, not simulated people, over how many real plus simulated will give you the fraction of simulated people. And if you replace n-sim by this formula, you get this, dividing by n or e up and down. All right, so now we have a formula. We have a formula that gives us the fraction of simulated beings. And at this point, I expect some of you to say, I’ve seen something like this before, just as crazy, just as useless, which is Drake’s equation. So this is Drake and Frank Drake. Drake’s equation is there’s some sort of crazy pitching numbers on the board and then writing an equation that follows from these numbers. But we can know what these numbers are. And the purpose of Frank Drake was to estimate the number of sentient beings in the universe or people that are sufficiently evolved that they could actually that we could actually pick up their signals. So that was the purpose of Drake, just to see, is it worth it to do a SETI type of research for extraterrestrial intelligence? Is it worth it to put radio telescopes listening to the cosmos, hoping to pick up signals from aliens? Is it worth doing that? And the answer is that we’re doing that essentially is what’s the probability that there is someone out there that was sending a signal that we might be able to get? And that was the purpose of Drake’s equation.

Gilles Brassard

00:34:41 - 00:38:07

It looks like this. Sort of reminiscent of the formula I gave you, just all sorts of parameters. And here, we’ll not go through that. I’m not talking about Drake’s equation here. But just to show you all these parameters that enter the game to determine n, which is what we’re after. And some of these parameters are reasonably able. We are reasonably able to estimate them today, which was not the case in Drake’s when Drake wrote the equation. For instance, what was the proportion of exoplanets orbiting other stars? We had no idea then. Now we have a better idea. So some of these parameters, we’re better able to estimate today than in Drake’s time. But still, some of them are just, come on. How can you hope to know the average length of time a civilization exists? How can we hope to estimate something like this? So in other words, yes, the formula makes sense. But it involves all sorts of parameters that we have no chance to ever be able to estimate in any reasonable fashion. And that’s the sense in which it’s sort of useless, although it’s beautiful. And you might think the same about what I told you. I have all these parameters. The last board was full of this and that and that and that that you all forgot them already, I suppose. But you didn’t forget how many there were, many of them. And there’s no way we can know what these things are. Now there’s a different Drake in me, which is that by magic, almost all of the parameters that I showed you will cancel out when we do the math, which Drake cannot hope for his purpose. So it doesn’t matter if you have any good idea what R can is, you don’t remember what R can means. You don’t need to know what it is. It’s going to cancel out in the math at the end. So that in a sense, it’s a more solid ground than Drake’s equation because of that, although it’s still crazy. Sorry. All right. So back to all these numbers. We need almost all of them. We can see that it’s really magic. All right. Let’s concentrate on these few. The fraction of individuals that belong to a Civ, the fraction of computing power they use to simulate consciousness, and the average number of brains that individual can simulate, which is very large. We don’t know how long, but it’s very large. Now, when you put all these things together with the formula I gave you before, the fraction of simulated being, remember, there were that fraction, right? So we don’t know at the moment, we don’t know any of these things. We can sort of try to estimate them, but we will not have to. But let’s reason without, maybe I shouldn’t have told you that it’s going to have a happy ending. But so let’s try to reason about this formula not really knowing what these numbers are. The only thing that we do know is that R cal is very big. So let’s see what happens if F civ times F ded is one over R cal.

Gilles Brassard

00:38:09 - 00:42:06

Now R cal is very big, so this is very small. This is very small. To say that this is very small means that at least one of them is very small. Now if F civ F ded is equal to one over R cal, it means that F civ F ded times R cal is one. This is one, this is one, one over two half. So if under this assumption, if this is the case, not assuming it, if this is the case, then half the people are simulated essentially. Okay. If F civ times F ded is slightly bigger like N over R cal when N is some number, like a billion, well R cal is very, very big. A billion over R cal is still very small. So to see that this is N over R cal means that this is very small, so that at least one of these two must be very small. Same conclusion. The difference is that now F civ is N over N plus one if you did N over one plus N. Very good. So in particular, so the number of simulated is this, therefore the number of real is less than one over N. Well, what if N is a billion? So if F civ times F ded is bigger than that in fact, what we get is that the fraction of real people is one in a billion. You may have heard that before. In other words, from what I’ve told you already, Musk, Elon Musk is correct, to some extent is correct that to conclude that the odds we’re in base reality is one in billions, if the product F civ and F ded is as big as this, is bigger than this, if it’s equal or bigger, then the odds we’re in base reality is one in a billion. Now let’s see what this means. So what does it mean? It means that F civ, that in the first, the fraction of simulated people is almost one, meaning almost everybody is simulated like us. Unless the only way to prevent F civ to be almost equal to one is to have F civ times F ded very, very small, at least smaller than one over Arcal, which gives us a half probability. So it has to be much smaller than one over Arcal for F civ not to be close to one. So now let’s, the meaning of these three statements, F civ is about one, F civ times F ded is about zero, which actually means that one of the two or both is very small. The only way for a product to be really very small is that each member of the product is small as well, at least as small as the square root of the product. Very well, so what does it mean that F civ is almost zero? What does it mean that F ded is almost zero? What does it mean that F civ is almost one? Let’s go through these three things. F civ almost zero, F ded almost zero, F civ almost one. Let’s look at these three things. And again, the conclusion is that the only way to avoid this is to have this and that. It’s a need of one of those, sorry. All right, F civ about zero means that the fraction of individuals belonging to Civ or the definition is that the fraction of individual that belongs to Civ, that’s F civ.

Gilles Brassard

00:42:07 - 00:46:19

F civ almost zero means that almost no one reaches Civ level in the universe. The fraction of people, of base reality people in the universe that reach Civ level is almost zero, here in particular. And now we’re back to Musk. The only reason that we would not at some point reach Civ level is that we self-destruct. All right, so if we don’t cease to exist, at some point in this reasonably near future, we will have the power to reach Civ level and create lots of simulations. Very well, so. F civ almost zero means that we cease to exist before reaching Civ level, that’s what it actually means. How about F ded being about zero, what does it mean? It means that when people reach Civ level, they have the computing power to simulate an immense number of simulated beings, but they don’t have to do that. Maybe they will use, maybe they will almost use none of this computing power to do simulations. That’s what F ded is zero mean. F ded equals zero means they have the power, but they won’t do it. Very close to zero means that they have the power and will use it very little. Now, what does it mean? It could be because there are taboos. When people reach this level of civilization, not only are they more advanced technologically than we are, but they are more advanced in ethics, perhaps, and there are rules and taboos that it’s not okay to create people and make them believe they exist when they don’t. That’s something morally wrong with that, so we won’t do it. And it could be taboos. But even if that’s the case, it suffices of a few rogue individuals. So that, sorry. So there could be taboos. But even if there are taboos that forbid people from creating civilizations, there could be rogue individuals like Lex Luthor in Superman. He’s very powerful, very rich, and very intelligent. And Lex Luthor, all by himself, could, if he reached Civ level, which he probably has, could harness an entire planet or solar system to use all the mass of a planet to be a computer and create so many simulated beings only by himself to override the fact that nobody else is doing it due to taboo. So in other words, it’s suffices of a few individuals who would challenge the interdiction to make F ded not so close to zero. He will not make F ded a half, perhaps, but it’s still sizable. All by himself, he can make F ded not negligible. So it’s unlikely that F ded is almost zero is somewhat unlikely. So this is unlikely. This we rather not think it would happen, but it’s not at all unlikely, by the way. Unfortunately, it’s not unlikely. But if this is not the case, if we manage to survive more than 10 years, then this should not be zero. And that should not be zero. And therefore, F sim has to be almost one. And again, F sim is the fraction of sentient beings who are simulated. So if you accept that this cannot be zero, and this cannot be very small, this cannot be very small, then you have to accept that almost all sentient beings in the universe are simulated.

Gilles Brassard

00:46:20 - 00:50:19

This is very much like Musk’s argument with more math in it, if you wish. Now, there is a big caveat here, which is that one should not equate the fraction of simulated people with us being simulated. Perhaps we are special. We’ve heard that many times in history. Perhaps we are special. Perhaps we live in the center of the universe. Perhaps we are special. We are special in the universe. Perhaps the only branch of the multiverse that really exists is ours. Anyways, so perhaps this is true. Most sentient beings in the universe are simulated, but does not apply to us in a way. All right, maybe you can believe that. I’m not going to argue against that. Because I’m going to have a much more important argument against the entire argument that I’ve shown you so far. So far, it’s really sort of mainstream in the sense that there’s nothing new in that. If you’ve been exposed to the Bostrom-Musk argument, nothing much is different in what I told you, except that there are numbers or symbols, more math, but it’s the same argument. Now we’re going to start having more fun. What is missing from these equations is the amount of computing power needed to simulate the simulated being’s environment. Bostrom acknowledges that we should take that into account, but says that it’s going to be very negligible because to simulate the environment of a simulated individual like us, so if we are simulated, to simulate my environment, all that’s needed is to simulate what I perceive with my eyes, which is not so many bits. So yes, yes, there may be a billion times more computation to simulate my environment and just myself, but not that much more. This does not take into account that we as individuals can use all sorts of instruments that go well beyond our naked senses and that require a much more elaborate environment to be simulated. So by CN, the cost of the environment, what I mean is what computing power is necessary to simulate each person’s environment, and I’m going to count that in terms, what the unit I’m going to use, the unit is how much computing power is needed to simulate that individual. Right, so the unit I use is simulating the consciousness of someone, meaning that if CN, let’s say if CN is equal to two, it will mean that to simulate me, my consciousness would take so much power, and my environment would require twice as much, so three times in total. So once we put the cost of the environment in the equation, then this equation we had, how many simulated people is the product of all these things that we’ve seen before? This is the amount, this corresponds to being able to simulate so many people, but now each time you want to simulate one of these people, you have to simulate the environment, which costs CN times more, so I have to divide by one plus CN to find the number of simulated people.

Gilles Brassard

00:50:22 - 00:53:49

This one is to simulate the person, and that’s to simulate the environment, so we can get fewer people. Fewer people can be simulated if the environment is taken into account. Very well. Now let’s see what this means. How big is this? And just throw in one more of these parameters that no one can ever hope to estimate. I’m just sort of seeing them getting things worse, but you’ll see that it’s getting better soon. So in order to simulate the environment, how big is it? I’m going to argue about this in a little while, but for the moment, let’s ask the following question. Can a simulated civilization create their own simulations? Remember, I told you about the Simulacron-3 novel, where the whole story is about that, that being possible. It’s not because it’s a science fiction novel, it’s possible, but let’s just ponder this question. Can simulated civilization create their own simulations? And now I’m going to argue that, well, maybe it’s not a yes or no answer, but I’m going to tell you the consequence of yes and the consequence of no. And the consequence of yes is really fun. Well, what I mean is, so yeah, there’s a base reality, and which creates nested, recursive nested levels of civilizations being simulated. Of course, you don’t really want to live here, because if you live here, and there’s a glitch of the world, and there’s a computer glitch happening at any level above your head, but that’s something else. So that is a picture you have, in fact, you should have in mind something more like a tree, because here, I simulate civilizations, but there’s another planet where you do, and in my civilization, maybe lots of people will simulate people, and each one of them will simulate their own people. So it’s a tree or a forest, it’s not just linear like this. But, so, let’s go back to the question. Yes or no? Well, if no, and that’s the really fun part, if no, then we’re done. Because as soon as we create our own simulations, if the answer to this is no, then we’re not a simulation, by definition. If simulated civilizations cannot create our own simulations, and we do create our own simulations, then we’re not simulated. End of story. And the only way this is so funny is that, that’s exactly Musk’s argument in the reverse. According to Musk, if we don’t self-destruct, this will happen. In other words, according to Musk, if the answer is no, then we are not simulated. Even though his whole purpose was to argue that we are simulated. Oh, see, otherwise, if he’s consistent in his statements, then we have to accept that simulated civilization will be able to create their own. Because if simulated civilization cannot create their own simulations, and if Musk is right, that we are going to do that unless we self-destruct, then we’re not simulated. Or we will self-destruct one or the other.

Gilles Brassard

00:53:49 - 00:58:08

Maybe if we self-destruct, we’re not simulated either. Anyways, so in the no answer, we’re finished. In the no answer, we’re not simulated. The yes answer is more interesting mathematically. If yes, then how much does it cost? And that’s where things will unfold. How much does it cost to simulate someone’s environment? Well, among all the civilizations, now we need to assume that everything is sort of uniform. It’s a big if. I admit it’s a big if. But if we assume that everything is sort of uniform across civilization and across simulations, same everywhere, at all levels, if we assume that, then the cost of simulating one person is that an effective fraction of the people that will be simulated will have reached Civ level. And when they reach Civ level, they will use an F ded fraction of their computing power to simulate more people. But simulating these people will take computing time. In other words, in fact, this is not the number of people they will simulate. The computing time, they will need to do that. So in order to simulate the environment of a consciousness who himself simulates other people, that’s a lot of computing time, the environment. Simulating that person is not so bad, but you have also to simulate all the simulation that that person will make. And that takes a lot of time. So now we get a bound on the cost of the environment on the assumption that simulating civilization will create their own simulations with a fraction F, F civ of them will do that. Very good. And then look at that. If Cn is, let’s say if Cm is, if it were equal to that, it’s going to be at least bigger. But if it’s equal to that, then one plus Cn is essentially equal to that as well. I’ll forget about the plus one. And this times this times this is this times this times that. And only n really stays there. So I promised you things will cancel out. So at that point, the conclusion is that the number of simulated people is less than the number of real people. So that is half probably real. Okay. And if the cost of the environment is much bigger back because people that… Sorry, I went over. All right. So if in fact the cost of environment is much bigger than that, then a very small fraction of people will be simulated. Like this. Now, if you’ve paid attention, which I would not blame you if you didn’t, because so many parameters that could make you dizzy or disinterested. But if you did pay really pay attention, which is that I just sort of lied to you. Because the argument that I use here is about comparing the number of people in base reality with the number of people in their simulations, but not in the simulations’ simulations. We’re not taking into account here. And if we might say, all right, there are much more people, many more people in real life than in their simulations. But these simulated people will create their own simulation in such great numbers that if you take every simulated being across all recursive levels, there’d be more than us if we’re real. So I sort of cheated you.

Gilles Brassard

00:58:08 - 01:02:12

All right, let’s do the computation slightly better. So how about the second level? We’ll get to the other levels afterwards. How about a second level simulation? Well, we’ve seen this formula already. This is number of simulated people at level compared to number of real people. How about a second level? Well, in fact, this same argument applies exactly to compare number of people at each level compared to the level above them. So if Ni denotes, sorry, so first person, let me do the divided by number of real people. So this is number of simulated people at first level over number of real people. And what I’m saying is that this same argument applies at each level. So number of people at level i plus one or number of people at level i where level zero is real, level zero is base reality. But number of people at level i plus one over number of people at level i, it can be exactly the same formula. If everything is uniform, again, it’s a big if. And then it’s just a geometric series. We call it FPOP. FPOP is the ratio of how many people at one level or compared to the level above. And therefore, number of people at level i is number of people in base reality times FPOP as many times as the deep just by following this reasoning i times. And i plus two over Ni will be Ni plus one over Ni, Ni plus two over Ni plus one times Ni plus one over Ni, which is FPOP times FPOP. So at each level, we get FPOP to power e people. And then again, just sum the geometric series. And you get a number of real people. Sorry. No, that’s the definition. The fraction of real people is how many in base reality over how many in total. How many in total, we just added how many people at each level, including base reality. Sorry, went the wrong way. And we get that number of real people is at least one over FPOP, where FPOP again is… Okay, sorry. Where C minus one minus number of, it is one minus one minus a fraction of real. So the fraction of stimulated people is less than what I call FPOP. And I remind that FPOP is defined by this. All right, so now what we have is that a fraction of stimulated people is no more than this. And this is what we’ve seen before in which CNV will cancel out with the other people. These things. All right, so to make a long story short, because you’re probably all bored by now, if we’re throwing more parameters, for instance, what’s the cost of simulating one computation operation? Because when at base level I simulate a consciousness, and he at some point builds computers, maybe or maybe not to make his own simulations, but when I want to simulate his environment, that means I want to simulate his computer, it’s likely to cost me more than one of my base operations to simulate one of his, because it’s a simulation after all. So we introduced this, we have already, we introduced FF, the efficiency of simulating computation.

Gilles Brassard

01:02:14 - 01:05:53

It doesn’t matter so much, but the point is that when you do all the math, we have this already, and we get that everything cancels out. Just trust me, you’ll do the math yourself. But at the end, at the end as a conclusion, the fraction of simulated people is bounded by F ded FF. And all the other parameters cancel out, that’s the point. All the others, that there is no way we can estimate, they all cancel out. Can we estimate these two? No, of course not. But they’re both at most equal to one. If they were equal to one, what do I mean that a fraction of simulated people is less than one, no big deal. But it’s unreasonable to think that F ded is bigger than C half. Can we imagine that people who reach C level spend more than half of their computing power simulating other people? Well maybe, but come on. So this is likely to be not all that big actually. There’s other things to do in life than simulating other people. But what do I know? But perhaps once we reach this level, that’s the only fun that’s left after all. Now the cost of simulating one computing operation is very likely to be, again, less than a half. Can you possibly simulate one operation, one computing operation at the simulated second simulation level by doing only one operation at your base level? Probably not. In other words, both of these are reasonably less than, I don’t know, let me just plug in the ridiculous number. 1 fifth and 1 20th, so we get one percent. Again, I’m not claiming that I have any way to estimate these numbers, but it’s reasonable to believe they are both reasonably smaller than one. And then the conclusion is that, it’s enough that one of them is less than one. Reasonably it’s less than one. It’s enough to conclude that a fraction of simulated being is quite a bit less than one. And that if we believe that the fraction of simulated being is a good indication of our probability of being simulated, if we believe that we equate these two things, then the conclusion is that we are unlikely to be simulated. Very well. Good. Now I’ll use my last five minutes to address the other part of the title. I told you about probability that we live inside a simulation, about consequences. Well, there are two main consequences that I want to address, only one of which I will have time to. One has to do with Fermi’s paradox. So I don’t have time to go through that. But Fermi’s paradox is an argument against the existence of extraterrestrials, because of the sentient beings, highly advanced extraterrestrial civilizations. And the argument that if they existed, why haven’t they come visit us yet? And it’s much more elaborate, but it’s an elaborate argument to the effect that really, because we haven’t seen them, they’re unlikely to exist, because they would have come if they existed.

Gilles Brassard

01:05:55 - 01:09:44

It sounds sort of silly the way I said it, but it is really more elaborate and more reasonable. Now Fermi’s argument, can be countered if in fact we live in a simulation. If we live in a simulation, remember the cost of simulating the environment. Well, in order to make this cost reasonable, our simulators would not go as far as simulate the entire rest of the universe with the appearance of life and creation of civilization and all that. I mean, to create our environment so complicated that would lead to emergence of intelligent beings on other planets that we don’t have access to, what a waste of computing time. So it’s very reasonable that in order to make CN reasonable, if we live in a simulation, in order to make the cost of simulating our environment reasonable, that our simulators will not create other beings that would come visit us, because we’re a waste of time, of their computing time. In other words, the fact that we have not been visited when we should, I mean reasonably, it’s unimaginable that there are no other very advanced civilizations having popped up in the universe and having created robots that would populate the entire galaxy. Even if it takes billions of years, their robots have the time to do that. It’s so improbable that this did not happen, yet we have not seen them. And the only reason, I’m going to joke a little bit, and the only reasonable explanation why Fermi’s paradox can be solved is that we’re simulated, and our simulators considered it would be too expensive to simulate the appearance of life on other planets. So this goes against the argument before this, an argument in favor that we are in a simulation, because if not, we would have seen aliens already. This is very shaky. Okay, by the way, Fermi’s paradox is neither Fermi’s nor a paradox, but that’s okay. No, but I want to come to the conclusion, which is the other issue, which is much more interesting, namely surveillance from above. If we live in, again, it was probability and consequences. Now we’re in the consequences if we live in the simulation. Now let’s be in the mood that we live in a simulation. What are the consequences? And being a cryptographer, and being someone who is very much interested in preserving privacy, of course I want us to be able to keep private from our overlords. Can we? So is there any way we can protect our privacy from them? What we cannot protect from them is that you can always pull the plug. No, so I’m not going to pretend there’s any solution. In fact, the only way that we can reduce the probability that they want to pull the plug is to be entertaining, which we are pretty much at the moment, by the way. I’m not talking about my talk. So let’s not worry about survival, just about surveillance. What can we do to protect our privacy from them if we are in fact simulated? And one could hope that quantum cryptography can come to the rescue.

Gilles Brassard

01:09:44 - 01:13:48

I promise you there would be at least one part of my talk having to do with this special day. Special day. So yeah, quantum cryptography is the only way known to us that can give us unconditional security and protection and confidentiality. Nothing else can possibly be unconditionally secure. So it’s the obvious attempt to protect us against, protect our privacy against the overlords. Now how would we do that? Well, quantum cryptography, of course, is unconditionally confidential, regardless of the eavesdropper’s technology, computing power, and here the eavesdropper is our simulators. So can we harness quantum cryptography for this purpose? And it’s not clear, because well, what would it mean? Our brains are, here we’re going to have to assume, of course, that the real world is quantum. If the real world is classical and they are simulating us, making us believe that the world is quantum, and forget about quantum cryptography. But why would they make their lives so difficult to make us quantum, which is so much harder to simulate if they’re classical, it sounds crazy. So it’s reasonable to assume that the real world is quantum as well. And they’ve simulated us at their liking. All right, so the world is quantum, they simulate us, we are quantum, and quantum information can be kept secure, even against unlimited computing power, and even against unlimited technology, so them. Looks good, but how can you apply it? How can you apply ideas of quantum cryptography to communicate with someone else, but more than that, to have your own private thoughts? That’s the main issue. How can you have private thoughts by using quantum cryptography when they can oversee everything, they cannot oversee, they cannot read our quantum things, but our brain is most probably classical. Some people think that the human brain is quantum mechanical, well it is, but that consciousness is a quantum mechanical fact. I don’t believe that, Penrose believes that, and Hameroff. But since our thoughts become classical in the brain, as soon as our thoughts become classical, we can be read by our world, it seems that there’s no chance. But now, there is something called delegated computation, in which, or some sort of more advanced than just quantum key distribution, quantum cryptographic protocols, by which we could imagine that we can build a quantum computer. This quantum computer will have as purpose to simulate us, not for the purpose of simulating other beings, simulate ourselves. So then I could project my own consciousness into that quantum computer, and now my thoughts will be quantum, and I could hope that once my thoughts are quantum, my own personal reality at the moment is not real anyway, so I don’t care dying. The only point is that the person that I think I am, that my consciousness would be downloaded or uploaded into this quantum computer, and then could be protected against them by quantum cryptographic protocols inside the simulation.

Gilles Brassard

01:13:48 - 01:15:04

It has to be done at each level of the computation, of the quantum computation that simulates me. I’m simulating anyways, so what’s the difference? But that doesn’t work. That doesn’t work because they will catch my thought before I can do it. I sort of created a circuit that would simulate, I’m at it here, so I created a circuit to simulate myself, which I put into that quantum computer, but before I can do that, they can divert my consciousness here and replace my circuit by theirs, and I would not know. So I would think that I’ve succeeded in hiding my thoughts from them, but I would have failed. And until now, we have not found a solution. So I’m very sorry to tell you that as far as I can tell, but we’re open to suggestions, but as far as I can tell, there’s no hope. We cannot protect our privacy against our overlords if we’re simulated, but maybe it’s just because I don’t have enough imagination. Let’s hope so. All right, thank you. Thank you very much. The paper is open access. The paper is open access on the Proceedings of the Royal Society, so you can go look at it if you want to.

Harry Buhrman

01:15:05 - 01:15:37

Maybe, thank you very much, you, that was fantastic. Maybe one or two questions and then, a break, Peter. Yes. I’m sorry, Peter. Peter, yes. What is this for? Okay. It’s a microphone that can be thrown around. Oh, I love that idea. Yeah, it’s very nice.

Audience questioner

01:15:37 - 01:15:53

Well, a major point you mentioned was how likely the being at some level is to want to simulate of other consciousnesses.

Gilles Brassard

01:15:53 - 01:16:09

Yes, yes. And I think that depends very much on the personality, the individual. There’s some people who would like nothing more than to make many identical simulations of themselves. Like crumb. Yeah.

Audience questioner

01:16:14 - 01:17:03

That was, actually, the other point I was gonna make that some of these ideas that the appearance of contradictions is evidence that we are simulations that are real. I think there’s a story of Borges about that where he says, I think he’s wrong about this, but he says the paradoxes of Zeno, the paradoxes having to do with infinity are so unreasonable that it’s evidence that the whole world that we see, including all of logic, is just a dream of God rather than something that exists.

Gilles Brassard

01:17:03 - 01:17:07

Sure. I agree with you to disagree with him. Yeah, okay.

Harry Buhrman

01:17:07 - 01:17:09

Here, somebody else.

Gilles Brassard

01:17:09 - 01:17:29

But still, the serious answer to it. I love this. The serious answer is that Peter wants to, oh, sorry. But the serious answer is that it’s an argument on average, which is meant to smooth out pathological cases, although smoothing out Trump is not easy. Or an exlucer, about the same.

Harry Buhrman

01:17:29 - 01:17:31

Peter. Yeah.

Audience questioner

01:17:31 - 01:17:48

My question is basically trying to connect this up to the construction of the self-replicating machine. Your model of simulation seems to suggest that the simulation is a step-by-step simulation of what is to be simulated.

Gilles Brassard

01:17:48 - 01:17:49

Yes.

Audience questioner

01:17:49 - 01:18:09

And if we take such a simple perspective at the self-replicating machine, it would mean that the self-replicating machine must have a copy of itself in itself. And we all know that the actual construction of self-replicating machines doesn’t do that.

Gilles Brassard

01:18:09 - 01:18:10

That’s right.

Audience questioner

01:18:10 - 01:18:26

So wouldn’t it be possible that the simulation works in an entirely different style of simulation than the naive one you’re using for your basic calculations?

Gilles Brassard

01:18:27 - 01:20:30

Sure. First of all, I certainly agree that most of what is very naive. But I think that the simulation is very, the question really, a different way, I think I’m asking the same question is, what’s the purpose of simulating these civilizations? Why would we do that? Why would they do that to us? And there are several different reasons why you might want to create simulations. It could be because you just want to play a video game. Play a video game. Or it might be because you want to project yourself in a simulation and be able to fly. Or maybe some sort of exotic tourism where you want to just experience the black death, not on your own, but experience being in, projecting the civilization where they are living or dying of that. Or you may want to simulate a civilization that’s much more advanced and project yourself in that. And there are all sorts of reasons. Another reason would just be to do sociologic studies, which was a reason in Simulacran actually, initially. So for some purposes, you want to, the same beings to be as close to you as possible, not you personally, but your civilization. For some other purposes, you want it to be very different. And I don’t have an answer, what would be the most likely reason to simulate civilizations. But then you could also want to simulate civilization that have different laws of physics. As I alluded to it, they make classical and us being quantum. And then the argument becomes weaker and weaker. Because when different laws of physics are being simulated, then them creating simulations is not so clear what it means, what power they need to do that. So anyways, all this to say that there are all sorts of loose ends in my argument, I agree. And what you say is some more of those.

Harry Buhrman

01:20:31 - 01:20:39

Great. There’s many more questions. Let’s do one more and then we go for the break. Mert.

Mert

01:20:39 - 01:21:05

So I mean, I was gonna say maybe relatedly. I mean, how do you factor in the fact that we don’t know what happens inside a black hole or more general, like there are bits and pieces of physical loss we don’t know yet, which could have profound implications on everything you said. I mean, with a lifetime of civilization, they could fall into a black hole and who knows, maybe that jump, they’re like plummets, FCM or increases, all sorts of things.

Gilles Brassard

01:21:05 - 01:21:52

Well, I remind you that according to Seth Lloyd, the ultimate laptop is like a little black hole. But no, forget about black holes, how about dark matter, dark energy? Yeah. Where what we know is only a few percent of the matter of the universe and the rest can do its own things we’re not aware of. So of course, there’s so much we don’t know about the laws of physics and our actual universe that again, to do any sort of more or less serious study of this topic, you need to make some assumptions that may or may not hold and I’m aware of that. And falling to black holes is something I have not considered, I must admit.

Harry Buhrman

01:21:52 - 01:22:22

Okay, great. Maybe I’ll interrupt it here. I forgot to say that Gilles is actually the first one occupying the QuSoft Turing Chair till mid December and so if you have more questions about this and any other matter, well, maybe not any, but quantum related other matter, Gilles is still here. And with that, I wanna thank you very much again for this wonderful talk. Thank you.

Gilles Brassard

01:22:22 - 01:22:23

Thank you.

Harry Buhrman

01:22:27 - 01:24:37

Yes, fantastic. Okay, now we come to the second talk of the afternoon and as your old guest, it’s Charlie Bennett who will give the second talk. And again, Charlie is one of the founding fathers of the field together with Gilles and Peter Shor and David Deutsch and I already talked actually a lot about his work because he and Gilles are somehow deeply entangled in a way that is mysterious and also very interesting for us. And as you know, entanglement is monogamous so we cannot actually see what happens between the two of them, but we can only see what comes out of it and it’s fantastic. Charlie has been working for IBM for a large part of his life and now he’s an IBM fellow. And besides working on quantum information processing as we used to call it in the old days, actually Charlie also worked on Kolmogorov complexity which was something that was also done a lot here in the old days, logical depth are things that Charlie pioneered and also reversible computation and in general, complexity of physical computation and computation in general. Besides the BB84 and the teleportation also worked on entanglement distillation and one thing that is always very amusing to see is that he worked on the reverse Shannon theorem, which is very nice. Besides the prizes that they share in common, Charlie also won the Dirac medal and the Shannon award and also a very long list that I’m not gonna repeat here. I’m very honored and very happy that you’re here, Charlie. It’s great to have you and you will talk about is there such a thing as private information and I guess in light of the previous talk, we have to wonder about that. Please take it away.

Charles Bennett

01:24:38 - 01:29:39

Well, I am very glad to come here because I’ve been meaning to come here for a long time and it was interrupted by the pandemic. This is a talk I gave in Poznań, Poland, originally before the pandemic and in Poznań, they have a walk-in version of one of the world’s most famous cryptographic machines. At one time it sat out in the street, I don’t know if it’s still there. So I’m gonna talk about the notion of private information and how it’s a notion that only exists in a certain approximation. In principle, I argue that it doesn’t really exist. There is no privacy. And then I’m gonna talk about different approaches to randomness generation and quantum cryptography. And I would say that at the outset, that of course different groups, different experimental groups or research groups pursue different approaches to the, they look at different parts of the elephant. And sometimes there gets to be a sort of institutional loyalty or rivalry. And Gilles and I can be seen as the aficionados of the prepare and measure kind of quantum cryptography versus the entanglement based. But I think that appearance of which of course the press sometimes catches up this appearance of rivalry. It’s really a natural and but should be spontaneous but it should be understood as not a rivalry but the way science and the cultures of science approach something that is new and complicated and not completely understood. And the relation that Harry alluded to between Gilles and me was part of that cultural accommodation because I was a physicist, I am a physicist and he was a computer scientist. So this question of how this got started had a lot to do with conversations between us and where I would speak of what something seemed to be, what the problem was as a physicist was, what the problem was as a physicist would see it and he would jump on it as a computer scientist. And I think that also occurred, I think that and Gilles would probably know because you had Richard Jozsa visiting in Montreal for a while. He was more of a physicist and I mean excuse me, was more of a computer scientist or a mathematician and his interaction with David Deutsch who joins us in this prize was also something that stimulated their work. Okay, so I’ll go on and now I’ll give my regular talk. He’s a mathematician, yes, that’s right. Well, computer science is sort of a, is really a branch of mathematics. Yeah. At least in some worlds, yes, okay. Okay, so what? Yes, but he thought of things very physically and he did some physics research, okay. And he was also an engineer. Okay, so I’m going to say is there even such a thing as private classical information? I have to say classical information because in this kind of, in this refined crowd, if I say information, you’ll probably all think I mean quantum information. So the difference is that that’s the first part of my talk and then I’m going to talk about the importance of doing it yourself. But getting back to the first topic, it seems like that there are three levels of privacy.

Charles Bennett

01:29:39 - 01:34:28

There’s the quantum privacy of a superposition and questions that have no answer like which slit did the particle go through before when it wasn’t being observed? And then there’s ordinary private information which we’re trying to protect. And then there’s public information. Now, the reason for a problematization or the question of whether there really is such a thing as private information comes from the fact that if you have a bit of entanglement between Alice and Bob, you can convert it to a bit of clear shared secret. So in a sense, entanglement is a resource from which you can produce shared private information. And that’s the whole entanglement based approach to the key generation. But it only works if Alice and Bob can keep Eve out of their local environments. And similarly, if you take a prepare and measure scheme for key distribution and you carry it out coherently, you get a procedure for generating entanglement. But now I want to say, is there even such a thing as classical private information because it seems in principle to be a slippery slope where you have quantum information and then classical but private in the middle in the unstable position and then public information at the bottom. And what makes private classical information unstable is decoherence. As soon as Alice or Bob records a secret key bit, for example, generated by quantum key distribution, in a macroscopic medium, it’ll begin to decohere relative to the environment just as Schrodinger’s cat is already decoherent before you open the box. Therefore, the key is not absolutely secure. You could in principle learn it by doing a very sophisticated measurement on the environment of the laboratory that contains this key. So they include realization of cryptology. Can you still hear me? There we go. You can deliver a key by putting it in an armored car, which is just a mobile version of keeping it in a locked safe. Now the quantum key distribution avoids the need for the armored car, but it still has the same problem of decoherence. So in principle, it could be broken by sophisticated monitoring of the environment. Now I thought about that a little bit as in the fashion of a physicist. But by this time I talked to Gilles enough to know that one of the maxims of cryptography is that you should avoid security by obscurity. A worthy, reasonable cryptographic system is one in which everything but the secret is public; the algorithm itself is not secret. Now if you look at a steel safe and under reasonably low magnification, you’ll see a lot of different grains of iron and different iron compounds. And then if you magnify it some more, you’ll see some crystal structures where there’s a lot of disorder or the way the crystals fit together. And I did a back of the envelope calculation and get about 10 to the 20th bits of obscurity in the transformation that the key undergoes in the process of decohering through a meter sized steel box. So this says, well, that’s maybe something we should think about in a little bit less orthodox cryptologic way.

Charles Bennett

01:34:28 - 01:38:25

How long would it take Eve to gather this, to figure out this function, this mapping of input output by monitoring the radiation that comes out of the box? Well at room temperature, you can figure out how much that is. And it turns out it’s not very nice. About a microsecond’s worth of outgoing radiation contains enough information to figure out that mapping. So that says, the nice thing about that though is we’ve got this cubic temperature dependence. So what about, let’s take our safe and cool it down to a few millikelvin? And that actually worked quite well. If it had millikelvin temperature, this time required to read the secret key goes on to decades or centuries. So it might be quite useful. But of course you can’t keep a secret forever at any temperature. However, before spending a lot of money on a refrigerated safe, you might take another factor into consideration. Avogadro’s number is very big. And if the safe has 10 to the 20th bits of frozen in obscurity, then even to store this amount of information and evaluate a polynomial time function of it is going to be infeasible. So the slope is slippery in principle, but in practice, not very slippery at all. So for practical purposes, it seems like that there are really three levels of privacy, quantum, private, and public. Now let’s look at this example of how this decoherence might occur. If I take a macroscopic key and write it on a blackboard and I accidentally leave the window open, it’s not secure at all. But if I close the window, and what happens is there’s a, and what happens is there’s a light that’s full of information about the key inside my laboratory, but it gets mixed or obfuscated into phonons and photons, which by the time they escape, you’d have to monitor all of them, which is quite, as I just said, is an infeasible task. But if you did, you would have memory, which would be a quantum memory, could save a superposition, if you could prevent them from getting out at all. But now suppose this becomes harder to get this memory really that well insulated because, let’s see, well anyway, we just, yeah. Oh, I know, yes, here’s what I wanted to do. I wanted to tap on, oh, I’ll skip that slide because it’s not working. Anyway, reasoning from classical mechanics, Laplace argued that the future and past were fully determined by the present, and attributed the perceived ambiguity of future to our imperfect knowledge of the present. And in the normal understanding of quantum mechanics, the future is less determined, but the past, we normally think of that as being determined, the past is well determined. But of course, some elements about the past, which we are not as quantumly literate people, we’re not allowed to call them that they happened, we said that the photon followed a superposition of paths, not that it did one or the other and we don’t know. So these are also elements of the past, which are not as real as a layperson would consider them.

Charles Bennett

01:38:26 - 01:42:37

Now, getting back to classical information, it’s tempting to believe that, and I think I even heard somebody say this earlier today, that classical information is, once it becomes public, you can’t undo the publication of information. This is a sore point between the American and the European notions of data privacy, what’s it called, the right to be forgotten. So anyway, it seems like the right to be forgotten is in bad shape now. But in the ancient world, it was quite common for major works of literature to be lost. And I think that this is actually continues to be true today, especially about information that people don’t care about. For example, I have photography as a hobby and back in 1965, I took a picture of these craters caused by raindrops falling on mud and then the mud dried out. And more recently, I began to wonder about whether the information in that picture exists in the universe somewhere or would have existed if I hadn’t taken the picture of it. And at first I thought, well, of course, it’s gotta be somewhere. But I think actually some of the information is lost not from the universe, but from the world, that is the planet Earth. And because there is such a large flux of entropy from the sun into the Earth and out into space, the Earth as a memory can’t hold it all. So I did a rough calculation and this is really rough. Fortunately, I haven’t submitted this for publication anywhere, so I haven’t heard it. When Gilles was showing me this, referee reports, I thought about how a good game for us scientists to play is to publish the referee reports, but not the article. And then give a, the prize comes to the person who can figure out what the article was best by looking at the referee reports. Okay, anyway, getting back to that. So I once, so I figured out that the thermal entropy export rate is around 300 watts per square meter. Well, that’s entropy, you have to divide by the temperature. And that’s about 10 to the 30th bits per square meter per year. And if you wanted to regard the Earth as a big tape recorder, which will store information for hundreds of millions of years, you think of the mid-ocean ridges where it’s rock is solidifying and continually spreading out and lasts at least for a few hundred million years before it gets subducted and melted again. And so we estimate about how much that is capable of recording. And that’s about what, it’s about eight orders of magnitude less. So there really is too much happening on the Earth for the Earth to remember at all. If you wanna remember things that nobody cares about. And to catch up with this thermal radiation, you’d have to travel faster than the speed of light. But it’s a worse problem than that as I was just explaining to Gilles because the what’s in various fields of science, there is what is called a standard model. And of course in biology, it’s evolution.

Charles Bennett

01:42:38 - 01:47:54

They don’t call it the standard model, but it’s the preponderant organizing principle biology. In particle physics, it’s the thing that they just discovered the Higgs boson to top it up. It’s still not perfect. There’s few loose ends in it. And in cosmology, the standard model involves an accelerating expansion of the universe, which means that once this, it’s worse than it’s just going away at the speed of light. It’s just that if it goes away farther than the Hubble distance, we’ll never see it again. Even if there was a mirror that far away and tried to reflect it back to us, we’d never see it. So it’s really serious loss. And as I was telling Gilles, that’s my favorite resolution of the Fermi paradox that probably there is some finite probability for technological civilizations. We certainly know what happened here, unless we’re somebody’s simulation. But why haven’t we seen others? It could be that they’re very scarce and there’s only not less than one per galaxy, but less than one per Hubble volume. Because the Hubble volume is finite, there are zillions of other civilizations out there, some probably nicer than ours, but we’ll never know about them and they’ll never know about us. So that’s why this is sort of, depending on your innate degree of optimism, this is either cheerful or discouraging. Anyway, we’ve added this new level of privacy, this classical but escaped information that’s been amplified to become classical, but it is escaping from the earth and we have no way of recovering it. And I’m gonna think about, contemplate some of these mysteries of the past. Here’s stuff that we’re pretty sure that is still present on the earth, but we don’t know, no one knows it, and it’s inaccessible with current technology. Now I hear that for quite a number of, even for several centuries, during the power of Venice as a seagoing nation, a city state, they would drop a gold wedding ring into the mud at the bottom of Venice Lagoon every year, celebrating Venice’s marriage to the sea. Now that stuff is very valuable, but apparently I’ve never heard of anybody at finding one of them. The first few of them would probably be much more valuable than their gold content by now, is historical artifacts. And then there are these lost classical writings and the fates of mysteriously disappeared people, two from what I’ve mentioned, one from the profession of physics and one from the profession of computer science, and one from the profession of being a corrupt labor leader. So I’m going to think about this in this sort of, think about this randomizing dynamics. If a raindrop originates in the quantum and thermal fluctuations in the atmosphere at all, a concrete physical manifestation, but unless the crater is lucky enough to get photographed or fossilized otherwise, it’ll get washed away. And there will be no stable earthly embodiment and the optical replicas of it that come from light shining on it and going off into space, there won’t be any more of those. So I’m thinking about, you could say the classical information of where it was is in the universe, but not in the earth. And so the ontological status of this, and this gets into which interpretation of quantum mechanics you like. And I belong to the many world sympathetic viewpoint. So you’ll be able to tell that from what I’m saying now. So let’s imagine a raindrop that falls in one of two places left or right. And after a while, we’ve got a situation where the brownish color represents the terrestrial degrees of freedom and the blue represents the celestial degrees of freedom. So it’s, of course, God sees this following in both places. And it begins to emit radiative replicas. And then after a while, there are more radiative replicas but the terrestrial replicas have gotten fewer, fewer degrees of freedom for pure.

Charles Bennett

01:47:54 - 01:52:03

This is just a cat state. And then finally, there’s nothing left but celestial replicas. And this sort of says that the escape of the last terrestrial replica from the earth, this restores the terrestrial observers to a more detached viewpoint. It’s really a kind of quantum eraser experiment that you make happen, not by undoing the measurement but by throwing away the stuff that you measured it in into a place where you can never get back. Okay, so now the idea that if you throw away enough of something after mixing transformation has happened, that will make it impossible to recover more than an exponentially small fraction of any particular bit that you wanna know about it. This applies both for unitary transformations and for random classical permutations. And it’s a sort of an idea that’s been absorbed into popular culture too, without that level of mathematics. You can buy at a typical flea market, a plaque that you can glue on your house or a tree or a rock or something like that. It says, yeah. But of course my approach to it was, I didn’t wanna shell out the $5 or something, so I just took a picture of it. So how would you get rid of the evidence of? Of course, I don’t think the people who killed them were this sophisticated, but that you would certainly cremate his body and let the heat and gases escape and then dissolve the remaining ashes and with no solid fragments and then pour them into the ocean. And of course, it’s very important not to tell anybody about it. And maybe for good measure, you ought to have yourself cremated and your ashes dissolved. So presumably if it’s done carefully enough, you would make Hoffa’s state terrestrially inaccessible, as like the way of last year’s raindrops. But suppose the killers had developed an attachment to him. So they wanted to keep him, not alive, but they didn’t wanna destroy him, just wanna keep him secret. Can you build a mausoleum for Hoffa such that his body would be preserved but no information about it would leak out? Okay, now this thing I just said before, I repeated that slide. So here’s my idea of the Hoffa mausoleum. We put, well, this is a one bit mausoleum. You put the bit in there and you insulate it in an insulated water jacket and then the whole thing rests inside of a big shiny mirror that reflects most of the emitted photons upward, away from Eve. So Eve will be able to get some of it, but a minority share, which will not be sufficient to tell her whether it was a one or a zero. But it’s tricky to get this thing to work well enough that it will work forever. So probably you can keep the information secret for a while, but if you keep the original in there, it’s going to eventually leak out. So it’s just, it’s a bad idea if you wanna murder somebody that you try to remember that you did it. So I think this shows that both in theory and in practice, the interaction between physics and computation is eventful and it will lead to further insights.

Charles Bennett

01:52:05 - 01:56:34

Now I have some slides here, maybe I’ll save it for the end, but I think the idea is that this is the part that I worked on with Graham and Debbie, showing why a private classical memory must be capable of storing quantum information. And conversely, if you let some subsystem escape, then it becomes a private classical memory, but not a quantum memory. I’ll save that for later. Now I wanna go on to my second topic, which is why I think do-it-yourself protocols for key distribution and randomness generation are superior in practice to device independent protocols. Now, let me review the kinds of randomness that people are trying to produce. There’s randomness generators, or used random numbers are used for various purposes, but whichever purpose they, whether you’re using it as a public randomness, for example, where you would wanna use it for making a fair decision in a lottery, or private randomness, which essentially is a cryptographic key, you want it to be of near maximal entropy. But those two applications are quite different. There is the, how many people have heard of the NIST randomness beacon? Okay, well, NIST in Gaithersburg, I think, maintains a public source of random numbers, which is in a locked and guarded room, and emits every minute, what, 256 or 512, some number like that, power of two, random bits with some certificate information about it. And the idea is that people who want to do lotteries or make a fair random choice, which people will believe is fair, can use this as a resource. Now, the weakness of that is that, of course, you can’t tell when a random number was generated by looking at it. So although the people at NIST know that this random number was just made, and they just, it was made less than a minute ago, and it was just broadcast, it could have been if the NIST beacon were corrupted, that they made it yesterday or last year, and just emitted it now, pretending to be freshly generated, and they sold advance information on this to an accomplice who would then be able to buy a winning lottery ticket. Now, Vadim Makarov, famous for his quantum hacking of quantum cryptosystems, and he dresses pretty much like a pirate, I took this photo of him in front of his explanation of why you shouldn’t trust anybody else’s random numbers. You see, he says, well, somebody says they’ve got a source of random numbers, and in fact, there is a mechanism for generating random numbers in there, but hidden in the works of it is a read-only memory which has prerecorded random numbers, and at a certain time, it sends these prerecorded ones out, which that’s the right time to buy that lottery ticket. This crime actually has occurred in the, I forget exactly who did it, but it was one of the engineers who put something in the code of generating random numbers for lotteries that made occasionally the output predictable, and then he didn’t actually sell it.

Charles Bennett

01:56:34 - 02:01:01

He used it as like a tool for socially ingratiating himself with people. He gave them hints as to when was a good time to buy a lottery ticket, and they won the lottery. Eventually, they caught him. Anyway, so as you can see, it can’t be generated from an honest one by testing its output, and because of the miniaturization of electronics, it would be very hard to be sure that a random number generator that somebody else made didn’t have something like that just hidden in it. It would be much easier nowadays to do than in the old days of cogwheels or even nonintegrated circuits. So this is in a way the trouble with using Bell violations for randomness generation. They’re planning to do that in NIST. I think maybe they’ve done it already, but in a sense, that is closing the barn door after the horses escaped. Has anybody here, everybody here who’s seen a horse in the last 24 hours, raise your hand. Horses were just, less than 100 years ago, horses were just, they’re a part of our language, but you hardly ever see a horse. Anyway, so where was I anyway? So anyway, so what, the people at NIST, oh, the horses gotten out of the barn. The thing is the big problem with the NIST numbers, well, first of all, the NIST numbers, yeah, the big problem with them isn’t that they might not have been random, it’s if you don’t trust NIST, and a lot of people don’t trust NIST. So it’s a kind of, in a way, it’s like a zero knowledge proof if you make your random numbers with a complicated piece of equipment that you’ve built yourself, and then you tell other people that that’s how these random numbers were made. That doesn’t protect from this Makarov fakery. They’d have to come and visit you and you’d have to come and visit them. Fakery, they’d have to come and visit your laboratory to really be sure of it. So how do you build trust? Well, I think the better way is, I emphasize this do it yourself aspect. You shouldn’t trust anybody else’s random number generator. And you can build it yourself, and if you want to XOR it with some commercial random number generators you’re probably okay. I’m talking about physical random number generators, not pseudo random number generators. Include bell violations if you think that nature is malicious or that you are so incompetent that in designing a physical randomness source, say based on radioactive decay or a lava lamp, or when I was doing this project involving beacons, one of the easiest ways was to digitize the acoustic turbulent noise generated by the ventilation fan on your computer and then run it through a, what do they call it, a randomness extractor, compress it essentially, hash it down to a smaller volume. Nowadays you could use a blockchain, but that’s only computationally secure to distribute the trust. Maybe the more information theoretically secure would be to have several of these random beacons that are administratively separate. So in other words, one at NIST, one at the American Civil Liberties Union, there’s already one in Chile, one in Brazil, get one in Russia, and if you have enough parties that are mutually distrustful and XOR them all together, you’re in good shape.

Charles Bennett

02:01:01 - 02:06:03

Now there is an attack on this, which is if you knew in which order the signals would be received, you could make one corrupt generator that would wait until everybody else had fired and then adapt their so-called random number to steer the XOR in the desired direction. And there’s a way of solving that, which is to have these independent beacons, and the NIST beacon already does this now. I think partly because I told them they ought to, is to issue with each random number a pre-commitment to the next one that’s gonna come out. So in other words, they would delay them for one minute. And so they would promise that they’re not storing the yesterday’s one and selling it to their friends, but they are actually keeping it secret for one minute because it’s in this locked building with hardly any wires going in and out of it and three people requiring a key to get in there, and you sort of trust them. So you trust them to keep it secret for one minute, and then unless you can computationally rapidly invert hash functions and so on, then this pre-commitment protects you from that attack. Now, I encourage NIST to explain not only build their own random number generator, but to publish blueprints or plans for doing it yourself because there’s no substitute for doing it yourself in order to be sure that you haven’t, it’s this thing like in the US elections, unfortunately, Dominion Voting Machines, I think, or has already won a lawsuit against Trump for accusing it of being rigged in a way that it isn’t. But anyway, if you suspect that sort of thing. So what you need is a plan for how to build a random number generator, even if you’re not an electrical engineering geek. And that would prevent amateurs from building a weak source. And then computer scientists will say, and this is part of the cultural difference because computer scientists, especially cryptographers, view nature as one of your adversaries. And physicists say, well, look, nature, we’re part of nature. Nature is, I forget who said this first. I think Einstein said it, but probably not first. Nature is subtle, but not malicious. And of course, cryptographers, they don’t like to deal with things that are subtle, they like, at least malicious, that at least you know what to do about it. It’s pretty much the same philosophy as lies behind the, don’t use security by obscurity because you’ll never know how much of your obscurity isn’t really obscure. So that cultural difference means that cryptographers, I think, and computer scientists are more distrustful of nature. But if you, like me, grew up as a physicist, then you can be pretty sure that maybe an experimental physicist, not a theoretical physicist like me, an experimental physicist, when the quantum cryptography apparatus that you can’t really see, the quantum cryptography apparatus that Gilles and I collaborated on, it was mostly built by my student, John Smolin, who had actual experience in labs. And when I got out of soldering irons and things like that and tried to make things work and align optical things, it was a very sobering experience. So anyway, if you think you’re a pretty reasonable experimental physicist, then you can be fairly confident that the uncertainty resulting from your accidentally creating a side channel where significant information leaks out about your private random numbers is negligible compared to the sense of security that you have from having built it yourself. So this is the kind of things that you can use for physical randomness generation. And the common features of it is that it’s a dynamical process that’s reversible, but infeasible to undo, and often involves the escape of some subsystem involved in the dynamics to an inaccessible place.

Charles Bennett

02:06:05 - 02:10:22

Now, of course, even though I’m not as paranoid as this would suggest, there are some people who try to be as paranoid as possible. And I think that means that you should not use anything that was produced during the microelectronic era. So since there are some fairly simple circuits for making physical randomness that just use a few components like transistors or vacuum tubes and resistors and capacitors, you could harvest those from old car radios. Now, the Trojan horse is really a rediscovery of something that’s been known for thousands of years. The proverbially unwise act of bringing an object that’s devised by your adversary into your own home. So in the device independence case, it’s unwise to suppose that the bell violating boxes are unable to covertly signal each other or an outside accomplice, or engage in other hostile activity like the original Trojan horse. A recent example of this is this wooden plaque that was not even that recent. It was in the, what, 50 years ago, something like that. More than that, almost 70 years ago, yeah. It was a big wooden plaque designed by the Soviet school children, and they gave it to the US ambassador in Moscow right after the Second World War, when it was, the Cold War was just warming up. I mean, just cooling down or whatever it did. Oh. And it worked. In it or anything that you could see, but inside the wood was a little acoustic chamber which would be modulated by air from the conversations coming through the eagle’s mouth or eye or something, and it was connected to just a straight piece of wire, but it had been designed by a very clever guy, Leon Theremin, who had actually visited the United States, but had been unable to get a job and was not sufficiently appreciated, so he went back to Russia and helped them build this. And it was used for quite a while. It wasn’t used all the time. The Soviets had a van with a microwave beam that they beamed at it, and then essentially this modulated the microwave beam so that by listening to the reflection of it, they could hear the conversation. And it wasn’t discovered until a British or US spy had intercepted a piece of Russian audio signal and recognized the voice of the ambassador and said, well, how did they get this? And then they took this plaque down and X-rayed it and you can see what was inside. So anyway, this just shows that there’s cleverness, especially with attacks that involve a covert channel, which you can only bring into function by sending some beam into the signal. It’s just why it’s, this is an illustration of the ingenuity of one’s adversaries. So this is why I say that do-it-yourself and measurement device independence, that combination is better than device independence for practical key distribution. And the reason is that in the device independent protocols, Alice and Bob used, they used to say that the disadvantage of the device independence was that it depended, that the key rate was very low and it depended on very high efficiencies and things like that.

Charles Bennett

02:10:22 - 02:14:39

That’s largely been conquered now. But I think this problem still exists because you, it’s so hard to prevent a device built by your adversaries from storing enough information and then later covertly leaking it. And then that allows your adversary to distill the same key you did. Let me just explain that how though. So it sounds weaker, but in fact it’s stronger because in the measurement device independent scenario, Alice and Bob send signals to Eve who makes the bell measurement and reports the results. And she can be as crooked as she wants because she can send what she generates to whoever she wants, but they only trust themselves not to have inadvertently created a covert channel to Eve through incompetent design. And by contrast with the device independent, they have to be sure that Eve has not deliberately building a covert channel. Now one of its more recent incarnations of this measurement device independence approach is really a return to the basics of the Mach-Zehnder interferometer. So instead of taking a signal and splitting it in two, you have two exquisitely synchronized lasers that are sources of identically frequency and phase, one held by Alice and one held by Bob. That’s quite a feat of engineering. But then if they each modulate them randomly by zero or pi, they can send it to a, here they each, okay, there we go. With the laser of Alice and laser Bob, and these are exactly synchronized. They each randomly phase modulated. And the result is reported by Eve here. And that means that she doesn’t learn their key, but they knowing their own phase and the result of Eve, they can get the, share the key. And this is a concept that I saw just a few years ago in the era when relations between China and the West were a little better than they are now. So this is based on a slide. Actually you can see roughly when this slide was made. It’s. Now can anybody read the caption here above Eve? It says made in North Korea. So that’s somebody that they neither trust, but this could be used for the Moscow-Washington hotline. Now, I said at the beginning that it may seem that there’s a rivalry between different approaches like, and indeed I’ve participated in this rivalry this afternoon by saying that measurement device independence is better than, and do it yourself is better than making random numbers key by Bell violations and procuring and then measuring entangled states. But in fact, in the history of this, the entanglement based approaches and the other approaches have been complementary. The easiest to understand proof of security of BB84 was based on thinking of it as a purifying, it is thinking of it as an operation on entangled states that never existed, but if they did exist, they would boil down to BB84. So that wasn’t the first security proof, but it’s the easiest one to understand.

Charles Bennett

02:14:39 - 02:18:54

It was based on this translating between entanglement based and prepare and measure. Also these explorations of correlations and what you can distill from them has enlightened the super quantum correlations. What kind of correlations could exist that would be non signaling and yet still something that you could distill a key from? There probably should be more collaborations between both those approaches. And one thing that I read recently was a paper that came out in Nature on device independence quantum cryptography QKD for distant users over a considerable distance, not as far as non device dependent, but quite respectable. Now the untrusted devices that Alice and Bob, you see when we were always talking about trusted or untrusted devices, trusted or enclosures, that they bring into their enclosures, I didn’t read the whole paper thoroughly, but as far as I can see, the untrusted devices are not big wooden horses, but individual strontium ions who have been prepared in an entangled state. And then they are bodily moved a short distance within the same vacuum state system to the place where Alice and Bob’s trusted apparatus perform measurements on them. So if you were to buy this apparatus from somebody, it would be very hard to know exactly where the division between the trusted and the untrusted part is. On the other hand, this strontium ion is arguably much harder to conceal something dangerous in than a horse. So I guess the moral of the story is that for sort of historical reasons, and the fact that unfortunately the lay public has hardly any understanding of quantum information and the foundations of it, and entanglement, it seems more like a rivalry than it should be. So the rivalry between randomness generation by device-independent methods or do-it-yourself no-nonsense just distilling noise out of a lava lamp, or the entanglement-based QKD or the measurement device independent-based QKD, they seem as rivals, but I think that they’re complementary approaches. And they also show how these idealizations that you make by saying, oh, it’s leaked out into the environment in such a complicated way that even if you could capture the whole environment, and even if P is equal to NP, but because there are 10 to the 20th degrees of freedom in the environment, you still couldn’t invert the function. These are all idealizations that break down at a certain point, and we should always keep that in mind. So it depends on what you’re trying to do. If you’re trying to build a secure cryptosystem, of course, everybody knows that the weakest part of it is the human part. But on the other hand, if you’re trying to make a nice theory of the relation between quantum information and secrecy, then you shouldn’t worry about that sort of thing. So I think it’s a good time to stop and ask your questions.

Charles Bennett

02:18:54 - 02:18:55

Thank you.

Harry Buhrman

02:18:55 - 02:19:29

Thank you very much, Charlie. Questions? People are very tired. Peter has a question. Oh, just throw it to him. I want to see that thing. I’m tired of doing this stuff. Actually, if I was the chair, I would stand here. You can do the next one, Charlie.

Audience questioner

02:19:29 - 02:19:47

Reminds me of advice I get from one of my cryptography oriented students who told me that if you want to have secure communication, do the encryption on the machine which is not connected to the internet.

Charles Bennett

02:19:47 - 02:20:15

Yes. In that regard, the NIST randomness beacon, I should have put the website, whether you can even go and find it. It has a big warning. Do not use these random numbers as your cryptographic key or password. They’re designed to be public. Everybody knows them.

Harry Buhrman

02:20:22 - 02:20:52

And Charlie wants to throw. Okay. No, no. This is more like it. Yeah. I don’t have any question. I just. I can give it to you. I can throw it. You want to think it’s a good thing. Well, I’m not very good at catching things but I guess it won’t suffer much from. Okay. Who wants the next question? Yeah. Jill.

Jill

02:20:57 - 02:21:11

So your statement about nature being subtle but not malicious, I think any actual quote from Einstein is not about nature but about God.

Charles Bennett

02:21:11 - 02:21:12

Oh yes.

Jill

02:21:12 - 02:21:20

More specifically, I think he said, and I quote, subtle is the Lord but malicious is not.

Charles Bennett

02:21:20 - 02:21:25

That’s right. But I think mine was a proper translation.

Harry Buhrman

02:21:25 - 02:21:26

This is not so hard to catch.

Charles Bennett

02:21:26 - 02:21:35

It’s that he also, when people bugged him about whether he believed in God, he said he believed in the God of Spinoza which is essentially his nature.

Harry Buhrman

02:21:37 - 02:22:02

I think we have one all the way in the back Charlie. All right. This means good. To the right, to the right. Okay. Well, this may be like a two hop. Don’t fall off the stage. I’m gonna throw it to somebody halfway there because I’m not sure. Okay. Okay. Well, that’s a frontal attack. Thank you.

Audience questioner

02:22:02 - 02:22:28

You were speaking about environment and to control environment is something of a thing as you know but my question is, are there cases where environment is rather controllable or rather simple in some way in applications or nearby? Well, the whole goal. Typically the environment is exactly that stuff you cannot control so that’s why this question.

Charles Bennett

02:22:28 - 02:23:21

Yeah, I sort of assumed that my environment was at least the proximate part of the environment was a steel box of static proportions but of course there’s things, yeah, there’s air currents in the room and everything else that gets more complicated but the other part of the question was are there situations where you try to make the environment very simple and that is the main multi-million or maybe even multi-billion dollar business of trying to construct a quantum computer is to keep the environmental degree of freedom as simple as possible and not by software techniques but by hardware isolation. So it’s teaching us more about how to simplify the environment.

Harry Buhrman

02:23:23 - 02:23:30

Great. Last question. Yes, well. You’re talking to the other end I think.

Audience questioner

02:23:30 - 02:23:44

I might have just missed this but on the topic of do it, you’re talking about the environment but I also want to play the lottery. How can we make public randomness if everybody makes their own random numbers? How can we still institute this?

Charles Bennett

02:23:44 - 02:23:53

Oh, I said this, yes. So I assume you want to play the lottery fairly. Yes, yes. Okay, well.

Audience questioner

02:23:53 - 02:24:06

Not really. I would love to win. You already explained how to play the lottery. You already explained how to do it unfairly.

Charles Bennett

02:24:06 - 02:25:04

Yeah. So if you want to do it fairly, you just make sure that the people who choose the lottery pick the winning number, not just by reaching into a barrel with their hand or something, the exclusive OR of the NIST beacon and the Chilean beacon and the Russian beacon and the Chinese beacon on a particular day at a particular hour. And then if, unless all of them are in collusion, that number will be randomly distributed. And then let’s say distributed between zero and 1,023. And then you pick your lottery. You don’t even need any randomness yourself. Just always guess number five. If the source is fair, it has a fair chance of winning.

Harry Buhrman

02:25:07 - 02:27:09

Good. Let’s leave it at this. Thank you again, Charlie. Some goodies, don’t go away yet. Some goodies here for you. And then now I would like to have some more technical help here because there’s not just two breakthrough prize winners, but there’s four. Oh, yes. Well, let me get this out of the way. What, the flowers? No, no, no, this, this. Leave the flowers. Yes. So there we have the other two, David Deutsch and Peter Shor joining us online. Look over there. Hello. Well, also congratulations to you, David and Peter. Fantastic that you’re here. I’m not sure, can you hear us? Yes, we can. Yeah, but actually so great that you’re here. We had just two fantastic talks by Gilles and Charlie. And now there’s not enough time to have both of you give also fantastic talks, but I thought it would be fun to just have a little bit of an interview with the two of you and then also with the four actually. So Charlie and Gilles don’t run away. So yeah, so you four are the founding fathers of our field and it was recognized by this fantastic prize that you won. But somehow you all four started at a time when the field was not existing really. And you wandered into it or you were working on it for some reason and maybe starting with David, why on earth did you start to work on this? And did you expect it, and that’s sort of the second question to become the field that it is now? So maybe you can comment a little bit on that.

David Deutsch

02:27:09 - 02:30:11

Well, I certainly didn’t expect it to turn into anything big, no. I started off thinking about what is now called quantum computers. I certainly didn’t even think of it as computers then, just quantum. Thinking of an experiment that would in principle test the Everett interpretation or Everettian quantum theory. And then several years later, well, it was Charlie Bennett’s fault, though I understand that he totally denies that this conversation ever took place. But I remember. We have to check that with Charlie actually, but please. So we were talking about complexity theory. I remember talking to you, but I don’t remember what I talked to you about. Ah, okay, well I can tell you. We were talking about complexity and I was saying that complexity theory is nonsense. And you were being very polite and you just said very mildly, why is it nonsense? And I said, well, because the complexity of a sequence depends on the computer that you work out the program that would generate it. And eventually you said, well, the computer is physics. And I was sort of taken aback and I had to admit that you were right. And then I said, okay, but if it’s physics, then you guys are using the wrong physics. And I thought I would, then I went home and I thought I would just work out translate Turing’s theory into quantum mechanics, expecting that it would all go over the same and that this would be a more secure foundation for complexity theory than using this Turing’s assumption, which is in fact false, that the world and its information content are classical. He unconsciously said, well, the world and its information content are classical. He unconsciously made that assumption. But then when I started to work it out, I realized that there was something new, that there was a new mode of computation was made possible by this. And so I thought, you know, that’s worth publishing. And, but I still didn’t expect this to turn into a real thing, let alone a real technology and a real field of science. Fantastic, yeah.

Harry Buhrman

02:30:11 - 02:30:54

And that it would give you this prize, right? Yeah, so it’s really all Charlie’s fault or Everett’s. I could say it’s Everett’s fault. In this world then, at least, yeah. So maybe let’s, thanks David, maybe we get back to that. But now I also wanna ask Peter, basically the same question. Actually, Peter, you are basically the latecomer on the block compared to the three we have here. Why did you work on it? And did you think of that it would have such an impact as it has now? So I guess I started thinking about quantum information

Peter Shor

02:30:55 - 02:33:17

When I saw Charlie give a talk at Bell Labs about BB84. And of course, he’s probably completely forgotten that because there were, we went around giving so many talks about BB84. But anyway, I thought about this question at the end of the talk that he asked, which is, is it possible to prove that BB84 is secure for a while and I didn’t get anywhere? And I, after a while, I, you know, Umesh Vazirani came to Bell Labs in 1992 and he talked about his paper on quantum computing with Ethan Bernstein. And then I started really thinking about quantum computing and went up and looked at a lot of older papers. Well, there weren’t a lot of older papers. I looked at the few older papers about quantum computing, including David Deutsch’s. And I started thinking about is something that would actually be a real interesting, not contrived problem that quantum computers would be good for. And I didn’t really get anywhere until I saw Dan Simon’s paper, which had, you know, used it for finding the period of a function over Z2 to the vector space Z2 to the N. And then, you know, I knew that periodicity was important for discrete logs and factoring. So I started thinking about that and they eventually got the solution. And I knew it was a big deal. I didn’t realize that it would span a billion dollar industry eventually. But, you know, I knew that everybody would be interested because it gave a, well, possible, but completely impractical way of breaking RSA. Yes. And in fact, the, you know, something like less than a month after we discovered this result, I was invited to give a last minute addition to the talk at the ad symposium. And someone from the NSA came up to me afterwards and asked me about it. Yes.

Harry Buhrman

02:33:17 - 02:33:46

And then of course, you actually told me also that the algorithm is sort of nice, but you thought it couldn’t ever run because of error correction, which then was the problem that you also solved a little bit later. And look where we are now in a world where everyone is afraid and talks about Shor’s algorithm and uses Deutsch model. And then hopefully BB84 comes to the rescue. Maybe just want to ask that question also to Gilles and Charlie, maybe first Gilles, …

Gilles Brassard

02:33:47 - 02:38:26

Why did you start to work on this? And at the time, did you have any epiphany of what it would lead to? All right. So why did I start to work on it? Most people here know the story, but I will say it again. It’s because one day I was swimming in San Juan in Puerto Rico, running my own business, when a crazy person swam up to me and started telling me he knew how to use quantum theory to make unforgeable banknotes. Someone had never heard of him, no clue who he was, that was Charlie Bennett. And so I listened politely to what he was telling me, which were in fact were ideas by Steven Wiesner, his old friend who passed away recently. Anyways, so if he had come to me while I was on the firm ground, I would probably have taken a run for my life, but since I was in the ocean, not a good swimmer, what could I do? So I just listened politely. I think from this point, we have to stop. To make the escape more difficult, right? So I listened politely and I realized that what he was telling me was not only impractical, but also useless. That Wiesner’s idea was completely crazy, not nearly as much as my talk of today, and when I say it’s a crazy idea, that’s a compliment because that’s the most beautiful ideas are crazy. Anyways, so I realized we’re not only impractical, but also useless because these banknotes could not be checked by anyone except the person who made them, so that you could not actually use them to buy candies or something. If you withdrew one of these banknotes from your bank account, all you could do with it is run around town and go back and re-deposit in your bank account because nobody would take them since nobody could verify validity. So it’s very nice nobody could make false copies, but nobody can verify validity, it’s not very useful, except the person who made them. So by the time we swam back and forth, I had found a way to use these new ideas at a time of public cryptography to transform Wiesner’s idea into a banknote that could be, that you need a secret to make it, that only the bank would know, but that the public information could be used to verify validity, and therefore it became, just as impractical as before, but not used anymore. And it’s somewhat ironic that my first contribution to quantum information was to turn a scheme of Wiesner that was unconditionally secure into one that was merely computationally secure. And so that’s right, so we had our first paper written while in swimming in the ocean, although only now hence, and then we went back ashore and began collaborating. And now to the second question that I think this was, would lead anywhere, as far as the quantum banknotes is concerned, no, I still think that it’s not something that is very likely to be useful, even though Peter Shor has done some really good work about that later. But, and it took us three years before we decided it was worth even publishing at the Crypto 82 conference. And then we continued thinking about this stuff and came up to a BB84, and then we, I don’t think either one of us thought that BB84 was something that would ever be practical, but I think it was something reasonable, and more than what we had done before at least. But it was not our day job, it was still, we were having fun, not taking this seriously at all, at least I wasn’t. And at least for several years, I mean, and then, well, just like Peter said about Shor giving talks on BB84, so I did, I gave, I think the first time that Umesh heard about it was from me when I was visiting Berkeley. And after a few years, I mean, we were giving these talks on BB84 and nobody took it seriously, some people had crazy, I mean, unfounded objections. But since we didn’t take it seriously ourselves, it was okay, I suppose. But after a few years, we decided that it was enough of not being taken seriously, and that’s when we decided to build the first apparatus.

Gilles Brassard

02:38:27 - 02:39:43

About five years after BB84 was invented, we created the first prototype. And then we got that published in Scientific American, and people began to take it seriously, which is really the most ironic thing because our theory was beautiful, whereas the apparatus was just a piece of junk. Not really, not really, of course, but it was, we could prove, at the time we couldn’t even prove security, when it was secure against any eavesdropper over a distance of 32 and a half centimeters, as long as the eavesdropper is deaf, because we could hear the photons fly by listening to the power supplies, and zeros and ones did not make the same noise. So this first apparatus was taken seriously when it was not in the least secret, whereas the beautiful theory was not, but that’s how it goes, and the rest is history. Well, certainly this, and then going to Charlie, who I have now found out is kind of the root of all quantum evil, maybe it seems to have started with you, Charlie, can you say a little bit about that?

Charles Bennett

02:39:44 - 02:44:45

Well, it really started before that, because of the idea that I told Gilles about, and that actually led to many other ideas in quantum information, came from Steven Wiesner, and he was very publicity averse. He had received at least one prize with us, Gilles and me, but refused to go pick it up. And we tried to persuade the Wolf Foundation to include him in the prize, but it was too late. And so we just wrote the… You can still look at it if you go to the Wolf Foundation, explaining his role, really, a seminal role in starting this. And as far as what he was thinking of, at the time, I’m trying to put that… I think it was his insight that quantum mechanics, and I’ll speak now of quantum mechanics the way it was generally understood by everybody. As Peter said, or me, excuse me, as David said, the idea that Turing had thoroughly captured the mathematical essence of computation, and that Shannon had thoroughly formalized the mathematical essence of communication, were very powerful ideas. And in fact, they reinforced each other in promoting a resistance to improving them, because people thought of… Of course, they knew about uncertainty principle, and quantum limits to computation, and quantum sources of noise. But they said, oh, well, this is something that Shannon has provided us with the theory of error correction. So we can… This is just an extra problem, a nuisance. Quantum mechanics was viewed as a nuisance. And then with the work of Bell and the proof of the Bell inequality violations, it was viewed, the way I would put it, as a philosophical conundrum, or more nastily as a way of forcing people who didn’t believe into quantum mechanics into more and more ridiculous epicycles that they were trying to put onto classical mechanics to explain it. But it was still a negative thing. And indeed, when Gilles and I started thinking about it, the thing that we were first interested in was the key distribution, which is based on a mobile version of quantum money. So it was the idea of using, in a cryptological setting, using a disadvantage as an advantage, because the disadvantage was… Affected your adversary more strongly than it affected you, your colleague. So then, but some of the other things that Wiesner did, and I was fortunate that he didn’t publish any of this thing except belatedly. But he told me about it before it was published. Eventually I wrote it up with him to get it into a physics journal, was this idea of entanglement assisted communication, which was a completely different idea and really showed how quantum information theory, as opposed to computation theory, was an elegant generalization of the classical theory. And this was, I was sort of present when Wiesner figured this out.

Charles Bennett

02:44:46 - 02:48:17

He, in his 1968 work, he was trying to find things that you could do with quantum information that you couldn’t do classically. And the two things he found were the unforgeable banknotes, which as Gilles pointed out were fairly useless because you couldn’t spend them anywhere except in the bank. And banks wouldn’t exist, that’s all they could do. And the multiplexing channel, which was the way of combining two messages into a single quantum signal from which the receiver could receive either one but not both. Well, that, we, Gilles and Stephen and I talked about that as we called it the quantum cookie jar. And the idea is suppose that you have a fat teenager who is very jealous of his own autonomy and you have two cookie jars and he insists on knowing their combinations and you say, you’re gonna get fat if you eat all those cookies. I’m going to send you a message which will allow you to decide, open one of the cookie jars, but not both. You can decide which one, I won’t know which one it is. And so this is something we could do with Wiesner’s other invention. Well, it turned out that cryptographers had discovered this idea, which was called oblivious transfer and showed that it was tremendously useful in negotiations between two mutually distrustful parties. And then the field, I mean, in terms of interest, one of the things that we pointed out in our, Gilles and I in our 1984 paper was how to defeat one version of this, well, essentially one version of bit commitment which was then generalized to show that this multiplexing or this bit commitment which was something that you could do classically only with computational security. And for a while we thought you could do it quantumly somehow with absolute security, but in fact it by an argument based on recasting a classical computation as a quantum computation, you can show that all quantum bit commitment is also insecure. So this just from the point of view of the gradual development of the elegance of the field as not just a nuisance, but a better way of looking at information and computation. As David said, what he said, and I think I’m getting to remember the conversation is, I said, well, I have this idea about how you categorize the amount of computational work that plausibly went into generating some physical structure. And he said, no, that’s nonsense. Computers are all different. I said, no, no, they can all simulate one another. And he says, yes, but they can’t simulate physics. You need a quantum computer. I said, what’s a quantum computer?

Harry Buhrman

02:48:17 - 02:48:45

Especially also David and Peter, Peter still has a day of Thanksgiving ahead of him. Have fun and David have a good afternoon. Thanks for joining in and congratulations again with the prize and the same is true here for Charlie and Jill. And then we are up for some nice drinks. So a big, big applause for them. Thanks for coming, Peter and David.

Peter Shor

02:48:53 - 02:48:56

Okay. It was fun. Yep.

Charles Bennett

02:48:57 - 02:48:59

XOR all those pictures together.

Markdown