ACM ByteCast - Charles H. Bennett and Gilles Brassard - Episode 91
Episode Date: October 1, 2026In this episode of ACM ByteCast, our special guest host Scott Hanselman (of The Hanselminutes Podcast) welcomes 2025 ACM A.M. Turing Award recipients Charles H. Bennett, IBM Fellow at IBM Research and... Gilles Brassard, Professor of Computer Science at Université de Montréal. Both are widely recognized as founders of quantum information science. Bennett is an American physicist whose research has shaped the foundations of quantum information science, quantum cryptography, and quantum teleportation, and who has played a central role in establishing quantum information science as a rigorous scientific discipline. Brassard is a Canadian computer scientist widely recognized as the first in the world to have delved into the uncharted territory of quantum information science. Their honors include the Wolf Prize in Physics, the Micius Quantum Prize, the BBVA Foundation Frontiers of Knowledge Award in Basic Sciences, and the Breakthrough Prize in Fundamental Physics. They are both members of the US National Academy of Sciences and the Royal Society, and Brassard is an Officer of the Order of Canada and of the Ordre national du Québec. In the interview, Charles and Gilles recount their chance meeting in Puerto Rico in 1979, which led to a remarkable and fruitful multidisciplinary collaboration. They highlight the role of serendipity in their own scientific discoveries and discuss how their once theoretical ideas became physical technologies, such as the first quantum-cryptography prototype, long-distance fiber experiments, satellite-based quantum key distribution, and rapid advances in quantum computing. They distinguish quantum cryptography from post-quantum cryptography and delve into the near-future implications of powerful quantum computers on information security.
Transcript
Discussion (0)
This is ACM Bytecast, a podcast series from the Association for Computing Machinery,
the world's largest education and scientific computing society.
We talk to researchers, practitioners, and innovators who are at the intersection of computing research and practice.
They share their experiences, the lessons they've learned, and their own visions for the future of computing.
I'm your host today, Scott Hanselman.
Hi, I'm Scott Hanselman, and this is another episode of Hansel Minutes.
Today we have the pleasure of chatting with Charles H. Bennett and G.
Brasar, they are the ACM AM Touring Award winners, and we have the distinct pleasure of speaking
with them in association with the ACM Bightcast. Thank you both for your time and for spending it
with me today. Is it in fact true that you met each other in Puerto Rico in 1979 and that
Gilles, you were swimming and Charles just came up to you because he'd heard you were interested in,
and the same things he was interested in?
That's pretty accurate, yes.
And the reason he knew that is that this took place at the conference.
And in the program, Charlie noticed that I would speak on the last day on cryptography and oracles.
And these were two topics dear to his heart.
In particular, he had submitted a paper at the same conference on oracles,
and his paper was rejected.
But he came and nevertheless.
And I remember, he told me about the contents of that paper, not that it had been rejected, when we met in 79.
And I remember at the end of my talk, or sometimes during my talk, I mentioned that the most exciting thing that happened to me at the conference was to hear about Charlie's idea about oracles.
And I hope that there were people in the program committee there who gringed because I was just telling them how wrong they had been in rejecting the paper, even though I didn't know it had been rejected.
or submitted.
So you each, correct me if I'm wrong,
but you each came at this from a different direction.
You know, Charles from the physics of information,
you from computer science and cryptography.
Is this a situation where the difference in your backgrounds
is actually necessary?
Because you can see something that you would not be able to see on your own,
and but together you're better than the sum of your parts?
Absolutely.
It's a beautiful example of multidisciplinary research
and really what we did came about from the meeting
not only of two people but of two fields,
namely computer science and cryptography on my side
and physics and physics of information on Charlie's side.
It's really because these two fields met in the ocean
in San Juan, Puerto Rico.
That's the meeting of the fields,
not just of the people that made all that possible.
And Charles, what did you see in Ju that made you think
this is the person I need to talk to about,
this. This is somebody who gets it.
Well,
nothing
originally. As he pointed
out, it reminded me,
a paper of mine
I think it was
the one on the random oracles, right?
That's correct. Yeah, that was rejected.
And that later turned into
a somewhat worthwhile paper, I think,
with
another person
whom I didn't, hadn't
met before going to the conference, which is,
John Gill, who is my co-author.
So I told them about that.
But the important thing about this meeting,
and that also emphasizes this interaction between the two fields,
which were much more separate then than they are now,
is that I told them about something I'd known about for almost 20 years
that seemed just like an interesting show.
curiosity about the way information behaved.
And he said, though this is important, it connects with ideas in cryptography, which I
hadn't heard about.
And which, so he said, you know, this stuff that you're telling me about, if it's really
true, we should write a paper about it.
And so I've been sort of sitting on this thing and telling people about it on and off.
Isn't this interesting thing without really taking it very seriously myself?
So he was the first computer scientist.
If I may interrupt, if I'm interrupt, sorry.
The main reason why I was the first person to be interested by you're trying to tell these ideas to many people is that all the others were physicists.
The others were for me.
He was saying that the others are physicists.
He's saying that you were running around telling everyone about your ideas, but the difference was you were telling physicists.
They thought it was interesting physics, but they didn't think it was.
They went back to their day job.
as doing other kinds of physics.
Right.
So bringing computer science into it makes a difference,
which makes me wonder, and I am not a theorist.
My degree is not in computer science,
but my degree is rather in software engineering.
And I struggle sometimes to bridge the theoretical to the practical
and I don't understand the leap that happens
or the work that happens in fundamental research
and then how it turns into something that affects my
my daily life. And I know that you both feel very strongly about the importance of fundamental
research, Gilles, particularly you feel that fundamental research is something that we're going to
lose sight of if we're not careful. Is that correct? Well, not necessarily, but it's something
that has to be encouraged and funded because, you know, innovation and what happens in the
in practical life is the end of a pipeline,
and a pipeline has several stages in it,
including marketing, innovation, all sorts of things,
but this pipeline starts with fundamental research,
by which I'm in research that is curiosity-driven
by people who have no reason to believe
that it's ever going to be useful for anything.
Research whose only purpose is to understand nature,
and then maybe it will remain sort of useless forever from a practical perspective,
or maybe there would be a completely unpredictable application that would come up years later.
And the best example of this is the development of relativity by Einstein and quantum theory
by Bohr and others in the early 20th century.
These people were doing this research purely for understanding nature,
and they had absolutely no idea that a few tens of years later,
the entire society would be completely transformed by their discoveries.
We would not have computers today, I mean not electronic computers,
without understanding of quantum mechanics.
And in fact, quantum theory appears in almost every gadget
that you have in your life today.
And again, we thought this fundamental research
that had no practical purpose whatsoever,
we would not be here today.
We would not be talking at a distance.
So fundamental research is absolutely essential
for science to continue,
but also for practical applications to follow.
Sometimes, sometimes not.
But you don't know in advance,
so you have to continue anyways.
I think the part of this that I would like to emphasize is that the reason it should be driven by curiosity is because if you try to make the basic research discoveries that you need in order to build something that you want to build, you will probably miss what turns out eventually to be important.
Interesting. So in other words, that's the reason that understanding, of course, there are engineering problems. Like you have to, you know, IBM, one of the things that they dealt with was some problem of electro-migration and they solved it by using copper instead of aluminum. So they were trying to solve a problem and they had, they did some applied research to solve it. But the examples as Gilles gave and many others.
You could say that number theory was invented by people like Fermat and was considered long to be among the most useless parts of mathematics.
And yet its application, what?
And it was called the Queen of Mathematics.
The Queen of Mathematics.
So why the Queen?
because number theory was very beautiful and completely useless.
So that's why they called the queen of mathematics.
And then, of course, number theory became central to cryptography
when RSC and Dvihimeland were invented in the mid-1970s.
Now, this is all going to fall apart when we have a quantum computer,
but still for half a century,
this useless number theory took center stage to,
attempts, unfortunately,
vain attempts at protecting our privacy.
I understand that both of you
agree that searching for things
that don't necessarily have practicality
is important. Simply exploring
because we are exploring matters.
Do you think about
there's a problem and I'm trying to solve it,
which is one kind of research.
I've identified a problem
and I'm going to work backwards from that.
And then there's the pulling on a thread,
on a sweater, like,
I don't know, I want to pull on the universe's thread
and see what was on the other side.
I'm curious, Jill, how do you approach that?
Are you more of an explorer or are you more of a solver?
Both ways, both ways.
Sometimes I have a problem that I find very interesting
and I work and work on it and bring my students to work with me.
And sometimes we manage to find an answer, sometimes not.
But at other times, for my most important discoveries,
with Charlie and others,
it was complete serendipity.
We were not looking for anything and just fell on our lap, like quantum teleportation.
We were not trying to solve quantum.
We're not trying to find a way to do what is now known as teleportation,
because of course that's impossible.
We were working on something else.
And the solution that came for the other problem was, oh, let's invent quantum teleportation.
And so complete, complete serendipity.
And same thing for quantum cryptography.
It was also a deputy that Charlie swam up to me
and that we started talking.
And then we started working,
having ideas on how to proceed further
and get more and more interesting ideas
along the lines that we set up initially.
But there was no, it was not that I thought,
I said, well, let's try to find a way to use
these ideas for cryptography.
It, we were, as you said, you was putting the thread, and it appeared by itself.
Very much rely on certainty.
But also sometimes, I have a pet problem.
I work on it, and sometimes not very, not so often, I get to find a solution.
Charles, some people have said when they have invented something,
whether it be a protocol or way of thinking, that they didn't invent anything.
They, in fact, discovered it or uncovered it.
It was kind of the theory that the information is out there.
It just needs to be observed and then written down.
Were you two inventing these protocols or discovering them?
That's a silly question.
Okay.
Thank you for that, sir.
Is that truly a silly question?
Is that an inappropriate question?
Because I feel if you accept the laws of one of the things.
It's not my favorite silly question, but it's like saying,
oh, if the world runs according to laws that are mathematical,
could it be that we're just in a computer simulation of the world?
That's not super.
It's a question.
It's along the same lines as whether the tree that falls down in the forest
doesn't make a sound unless there's somebody here.
Okay, I agree to the last one is silly, but not the first one.
One of my favorite papers of mine is,
all about the simulation question.
Do we live in a computer simulation?
And I'm very proud of that paper which I published in the Proceeding of World Society of London.
Well, why don't you just say that we live in the equivalence class of a possible real world
and in all of the simulations of it?
And that's all we can say about it scientifically.
As opposed to in superposition?
As opposed to what?
In superposition.
Yeah.
I do appreciate both of your perspectives.
When I do an interview, I'm always hoping someone will say,
oh, that's a good question.
That's a thoughtful question.
I think that's a silly question.
You're going to get the opposite response most some of the time.
Well, you won't know.
You don't know until you observe it.
So I appreciate your honesty in that.
I just, I'm curious, though, because there's an enormous gap between the elegance of quantum
of information theory in its theoretical sense,
and the engineering required to realize at its scale,
and I'm trying to figure out how those jumps happen.
Well, I'd like to draw your attention to something else,
which is, aside from looking at things
just because they're interesting,
it's fascinating,
there was something that drew me to the,
questions when I first heard about them from my late colleague and classmate Stephen Weisner,
which seemed intrinsically interesting and it caught Gilles right away as pointing to something
that the founders of information processing, namely the Mishannon and Turing,
left out.
Of course, they
left out a lot of things deliberately
like whether the message
was carried by
punched card holes
or radio waves.
But what I
saw was this example
from a weasner of
multiplexing
two messages into a form
for which the receiver
could receive one, but
in doing that would destroy the other.
And then, of course,
Laura and Laura could choose which one to receive.
Yeah, could choose either one,
and even the receiver wouldn't know,
the sender wouldn't know.
But so this said, this seemed to say to me,
of course, the information technologists
had a tremendous chip on their shoulder.
They thought they,
because they had revolutionized the world,
they pretty much understood everything about information,
And this was a physicist, this colleague of mine, who said, well, wait a minute, some of the information doesn't really behave that way.
You can't copy it.
Or if you try to read it, it'll disturb it.
And one of the things that you can do from that is to put this seeming disadvantage to an advantage by making this sort of self-destroying multiplex message.
Of course, I guess we have social apps that promise to erase the message after you.
Yeah, but you just have to trust them to do that.
So this, when I first heard about it, it said, you know, this is a very fascinating thing about information.
I wonder if any of these information theory people are interested in it.
And I tried to explain it to some people.
And Jill and I, and not too much later, tried to explain it to some professional quantum optics people.
And they said, oh, you know, you guys just don't understand what you're talking about.
So there was a bit of arrogance on both sides, which we helped overcome when brought the two fields together.
I'm curious, have, again, I'm hoping this is now, now every question is potentially a silly question, so I've got a little bit of analysis paralysis.
But I'm curious, have you now in the 2020s spent time with a quantum machine and thought back to the, we've.
were thinking about this in the 70s, 80s and 90s, and now here I'm looking at the thing.
I'm just curious about the scope of this amount of time that has passed. And if you've actually
been able to spend time with physical realizations of things that you thought were theories in
1993. Well, better than that, we build the first. The theories are still there.
Yeah, sorry. I said better than that. Well, we've spent, both of us spent a lot of time with
implementations of quantum cryptography. Of course.
And with very rudimentary quantum computers that they've been able to construct so far.
But I think we're not discouraged that it's a big slog, and it takes a lot of engineering work.
Jules, you were going to say?
Well, not only have we been in contact with physical realizations of our ideas,
but we actually built the very first prototype.
Yeah, right, first.
Indeed.
But for the cartography, about five years after inventing the protocol and exactly 10 years after meeting in the ocean.
Right.
But other than that, we're not, Charlie and I are pure theoreticians.
We're not experimental physicists.
But I have kept in contact with some experimental physicists who are implementing these ideas on a large scale.
started with Nicola Gizain in Geneva
was the first person to implement
quantum cryptography over tens of
kilometers of real distance,
not just a coil,
a spool with fiber optics,
10 kilometers long,
but then Alice and Bobbar links to each other.
But the real physical distance,
the first time was Nicola Gizain,
who did that under Lake Geneva,
to link Geneva with neon
and later with Lausanne.
And more research,
In China, there's been extraordinary work, practical work,
not for implementing quantum cryptography on a lower scale.
They have 10,000 kilometers of what they call the backbone
of quantum cryptography, which is fully integrated
with their space version.
So they have satellites and they can do quantum cryptop
between the satellite and the backbone and back.
And so at the moment in China, it's amazing.
how well they are equipped
in implementing our ideas
for quantum cryptography.
There are less than I heard
5 million users already
of quantum cryptic China.
Now, you were just there?
Is that correct, sir?
Yes, yes, yes.
I was there just a few weeks ago.
That's right.
But I did not visit their laboratories.
I gave talks
and I met,
and I spent several days
with the person
who's really the chief, the top leader
in experimental quantum crypto,
named the Ghanwe Pan, known as,
sorry, I'm not here, doesn't matter.
And it was very, very pleasant time with Ghanwe.
We discussed some of his newest achievements,
but we did that in the desert,
Gooby Desert riding camels.
So we didn't get to actually,
I didn't get to see the apparatus or anything.
But if I saw it,
they were in no different,
I would not understand it.
Whereas I understand the theory,
and I love talking to people,
including experimentalists about the theory.
Right.
So then like the satellites,
the quantum experiments at space scale,
these are all 10 years old now.
So these quantum,
quantum key distribution experiments that were decoy state BB-84 protocol were deployed over a thousand kilometers.
Well, yes, that's correct. That's right. The first space experiment done with satellite misuse was in 2017, I think.
So, yes, it's 10 years old. But they've improved tremendously since then. They've built small.
better and smaller satellites, more of them,
smaller and smaller receiving stations back on Earth.
In the original version, you would need several months
to build a receiving station.
Now they have one in a truck and they can deploy it in hours.
They can bring it anywhere they want and deploy it in hours.
It's enormous progress in the field.
As there is enormous progress for the building,
building a quantum computer about which we haven't really talked so far.
So quantum computers are really fascinating, but that too is something for which there has been
enormous progress, technological progress in the past few years.
ACM Bytecast is available on Apple Podcasts, Google Podcasts, Podbean, Spotify, Stitcher, and Tunein.
If you're enjoying this episode, please do subscribe and leave us a review on your favorite platform.
I have heard of people, I think I would say that the rank and file software engineer, the kind of people that I talk to every day, are not thinking about post-quantum cryptography.
But there is a growing group of people who have deep concern that this is something that's going to happen and it's going to happen very quickly.
I'm curious, where should my, where should I, where should my feelings be around post-quantum contogatory view, but somewhere between panic and enthusiasm?
Or panic, total panic.
But you see post-quantum cryptography,
maybe you don't know, maybe you do,
the difference between post-quantum cryptography
and quantum cryptography.
That's a great point.
Very different things.
Quantum cryptography is what you and I invented,
1984, 83, actually,
by which we use the laws of physics
to transmit to establish a secret key
that is unbreakable by the laws of physics
as long as the apparatus is built correctly,
which is not an obvious thing to do,
whereas what is known as post-quantum cryptography
is an attempt to use purely tacical techniques
to achieve the same goals
as what RSA and Dvieve-Hellman
and the current cryptographic infrastructure
which would completely fall down,
fall apart when a quantum computer is available.
So people are trying to scramble
to find different ways
to achieve the same benefits by purely classical means,
but that would be unbreakable by quantum computers,
since we know that the current infrastructure is available.
The trouble with this is that post-quantum cryptography
is trying to build something, to design something
for which we have absolutely no idea
how we can even start to think about how to prove it's secure.
And so all of this post-quantumptography,
Crypto by definition, by definition can be broken with unlimited computing power, whereas
quantum crypto cannot.
And moreover, post-ponum crypto is based on beliefs.
It's really wishful thinking that what they're inventing will indeed be unbreakable with a
quantum computer.
What could happen is that not only is it vulnerable to quantum computer attack, it could even
fall against a classical computer.
because what is used in post-qu quantum crypto
are problems that are sort of new
that have not really been studied for centuries
was RSA was based on factoring,
which was a very old problem
when it was good reasons to believe that factoring is hard
and a big surprise that quantum computers can break that.
Whereas the post-quantum crypto that is being developed,
there's absolutely no reason to believe
that any of that offers any security.
So yes, sir, yes.
I would say not absolutely, no reason.
Really? Okay.
Because they look for things that look different enough from fracturing,
that if, for example, as a lot of people suspect,
one-way functions still exist,
and so P is different from NP, that could also happen.
We don't know.
I mean, all classical cryptography,
except for the one-time pad and quantum cryptography
are provably insecure.
Yes.
But may be practically secure
if certain hard problems are really hard.
Well, now, factoring used to be thought to be a hard problem,
but it's not hard anymore for a quantum computer.
So the quantum in the phrase,
in what you might call a marketing phrase,
post-quantum cryptography,
is post-quantum computer cryptography.
not post quantum cryptography
cryptography.
The reason that our kind of quantum cryptography
isn't a total solution
is that a lot of nice things
that you can do with the information infrastructure
like digital signatures
and well especially
public key cryptography
where people who don't know each other at all
can make sure who they're talking to
and that they're messengers.
That's harder to do with
with quantum
cryptography
with absolute security
Oh yeah
I see
quantum cryptography
solves the problem
of secure communication
yeah
confidential communication
does not solve
many other problems
that
that post quantum
crypto has a chance
to solve
even if we cannot
prove it does
but then we come back
to should we panic
the main reason
to panic
is not what I just said
it's much much worse
but by the way
When you ask you, we should panic,
I should have jumped on it and said,
what a good question.
That would have made me feel better at this point.
I'm sorry I didn't say it immediately, but it is.
So the reason we should panic,
the main reason is that it's known as the Harvest Now
and the Crypt Later paradigm,
by which nothing prevents an opponent
of intercepting all cryptic communications
that go on the Internet.
just copying them and storing them and keeping them at home.
So all this cryptid information can be already stored somewhere,
probably is actually,
in the hands of would-be opponents who are totally unable to decrypt it
because they don't know how to break RSA yet.
But whenever a quantum computer becomes available to them,
they can go back, take it all out of storage,
and decrypt everything retroactively.
In other words, because RSC and DFIHeneland were essentially the only crypto tools used
ever since the little padlock appeared in your browser to make you believe that it is safe,
ever, almost every communication from that time, from tens and tens of years,
was encrypted using RSC or DFE Hanlon.
Both of them were broken with a quantum computer.
In other words, whenever the quantum computer becomes available,
everything that has circulated on the internet
becomes an open book retroactively.
And worse, there's nothing you can do to prevent it
because this cryptid information is already
in the hands of the opponent.
You cannot take it away from them.
You cannot prevent them from decrypting retroactively
when you have a quantum computer.
There's nothing, absolutely nothing you can do
to save the past.
All you can hope for is save the future
by using different techniques,
either quantum or post-qu quantum crypto.
And in case of post-Quatum Crypto, you also have faith.
But of course, quantum crypto also need faith.
For quantum crypto to be,
quantum crypto is proven secure, absolutely secure events against an opponent
with unlimited computing power and unrestricted technology.
But it's proven secure under two conditions.
One is that quantum theory is correct, and we don't know that.
And the other is that it's implemented correctly, which is hard to do.
So a neither is perfect.
So if it's to paraphrase and make sure that I'm understanding,
if post-quantum cryptography as a software-based defense
is going to ensure that today's classical communications
will remain secure against future quantum computers,
while acknowledging that there's a significant window
where we weren't doing any of that.
No, no, no, no, no, no.
Post-quant crypto, if we switch from the current infrastructure
to post-quantum solutions today.
And by way, we went to years to do that.
But if we switched today, it would not in any way ensure safety in the future.
That was my question.
There's no guarantee.
Nor safety of whatever will be encrypted between that moment.
We switch to post-Quatum crypto.
And a later time when perhaps someone finds how to break it.
All of that can be broken retroactively in the same harvest now decryplator of paradigm.
And in fact, the main advantage of quantum crypto, in my eyes, is not that is provably secure because it's not, if it's not able to correctly.
The main advantage of quantum crypto is that it's not subject to harvest now the crypt later attack.
And if an eavesdropper has found a way to break into, to exploit some weakness in the implementation,
which allows him to obtain the key without being detected.
And that's not impossible because if there are imperfections in the implementation.
But if an eavesdropper finds a way to do that,
he needs to apply it while the communication takes place.
There's nothing left for the eavesdropper to work on afterwards.
So the real thing about quantum crypto that we can be proud of is,
and here I quote Norbert Lutkenhouse from what is a word,
When you use quantum crypto and quote, now I quote a little in house,
the key will remain as safe for eternity or forever as it was immediately after transmission.
I see. I see.
I really think of quantum crypto's main advantage that there's no possibility for bad people
to store anything in order to decrypt later.
If they find in 10 years, they find a way,
oh, there was a weakness in the implementation of,
that these people used 10 years ago.
Well, it's too late.
No use to that.
Interesting.
When you were saying that, it popped into my head
that the universe has created a one-time pad for us to use
and it will be inflated one day.
I saw you moving there, Charles.
Did you have something that you wanted to add?
Oh, well, actually, the most,
of, no, no, I don't think I wanted to add anything there.
I was going to make a somewhat facetious remark.
So speaking of the panic now and decrypt later approach,
one thing that we can do about the insecurity of the stuff
that's already been harvested, of course it can be used
if if some of our communications are of diplomatic or military interests, they can be used for
purposes of national competition and security and so on. But they can also be used for blackmail,
like if you said something embarrassing in an email at one time. And we can't destroy this
information feasibly. But what we could do,
do is publish multiple additional copies of it so that the price that the blackmailers will charge
gets depleted by an excessive supply and you don't have to pay so much to get them to not
they have less of a no one blackmailer can threaten you as badly so you say you know why it's going it's going to
be published anyway, you know, make my day instead of, okay, here's your money.
There's going to be a lot of very interesting ethical and societal questions that will be
explored when all of this stuff happens. I'm curious, when we say that this is emergent and
that it's coming soon. I've long felt that everything is soon. It's just five years from now.
It's always five years from now. So just end plus five. Do we have a sense of,
of how imminent these things are gonna happen,
or is it one of those things where we're gonna
overestimate how long it happens
and then underestimate the impact?
You're talking about having a quantum computer
powerful enough to break cryptography?
And affect my life and the life of people
who do not understand such things,
but rather see its effects?
Well, it should affect your life already.
Okay.
Because of what I explained, even if no,
first of all, we don't know,
there might be already a full-scale quantum computer running somewhere in the basement of someone.
So we don't know that.
We have no way to know.
That is not the case.
But as I just explained, not only should it already impact your life because you should worry about what's going to happen, even with retroactively.
So nobody should just sit down and relax and say, well, I'm going to worry whenever it happens, because then it's very much, much too late.
It would be like not taking care of climate change and saying, oh,
we're going to worry when the earth is destroyed.
Right. And, and of course, society would never do that.
I know, of course, no. No. No. Goodness, no.
Wow. So given that the panic time is now, how can one use this information in their life
and make good choices and good decisions so that they don't get burned later? What are the
kinds of things? What is the equivalent of, you know, reduce, reuse, recycle when one is
thinking about information science in this way?
I don't have any particular advice other than just generally not saying things that you'll be embarrassed if they leak out.
Always good advice. Always good advice. Evergreen advice indeed.
Yes, yeah. Well, other than that, it's don't blindly trust the current infrastructure.
Be aware that everything you say on the Internet is susceptible to becoming known at some
future, which
when is not clear.
So be aware of that
and therefore, yes, don't
see what you might regret later.
Or else,
buy yourself quantum cryptographic equipment
to talk to
your friends. Yeah, which is in my
basement, actually. I forgot to tell you.
Also, about
when we'll have a quantum computer
powerful enough if there's not one
already. No, I'm not going
to tell you in five years. But what
I can tell you is that there's been unbelievably fast progress technologically in the past few years.
So, and this, it's very, very clear.
Nobody can say, just close their eyes and say, oh, it's never going to happen.
15 years ago, it was okay for someone to say not.
There's still a few people who say that, but they're not.
But, you know, in the last year or two, maybe three years, it does feel like we're starting
the beginning of the hockey stick upwards in that space.
That's right, that's right.
There's really been extraordinary progress,
technological progress,
to make us believe that it's coming up soon.
Now, how soon I don't want to try to predict.
Yeah.
Well, thank you both for your time
and for your contributions to the space.
We appreciate you very much,
and we appreciate you taking time to chat with me
on the ACM BICAST.
Thank you so much, both of you.
Well, did you want to hear about
to a part of the expression, artificial intelligence?
If you want, I know that some of us are interested in the topic.
I think I would be interested, Charles H. Bennett, in your perspective on AI as it relates to it, taking my job away.
But I want to ground it in some kind of tip or facts that I can take with me into my day and how I should feel about it.
If you have something you'd want to share, certainly feel free.
Well, I think the reason this hurts more than when machines were able to take over other routine activities
is that people think of scientific research and the kind of work that mathematicians and
theoretical physicists,
trying to prove things as like the highest,
the most intellectually challenging human activities.
So if they,
if they,
if computers can do that so better,
so much better,
then what is there left for me?
And the,
the example I'd like to bring up here,
is something that comes from computer science.
Okay, yes.
So I'm going to take some part of theoretical computer science,
which is known to many of the people in the ICM,
but maybe not all of them.
And this is what's called the theory of interactive proof.
And this involves the question of...
Questions that you can, normally, complexity classes like P and NP and P space have to do with how much of some resource, like time or space you need to use in order to solve a problem.
But this is a problem-solving situation in which there are two participants or two kinds of participants.
there's a honest but limited participant that's nicknamed Arthur
and an infinitely wise but completely untrustworthy participant called Merlin,
like to the Merlin the magician.
And the idea is, is there a way for Merlin to convince Arthur that something is true
that Arthur couldn't convince himself was true
just by trying out whatever all of the tests he needs to do to find it,
because it might take him too much time.
Now, well, the theory of interactive proof says there's several results in it,
but one of them, one of the most famous results,
is that if Merlin and Arthur interact for just a polynomial amount of time,
then Merlin can convince Arthur of the truth or falsity of any question that Arthur by himself would require
polynomial space to solve.
Another is something that appears to include exponentially harder problems, including most of those of interest to mathematical physicists.
Of course, it's an unrealistic model because it involves this character Merlin, who is supposed to know everything,
perhaps even the solution to the halting problem,
but just giving Arthur the opportunity to talk to him
and ask him adaptive questions,
where if he starts lying, Arthur will catch him within a polynomial amount of time,
that gives this much greater extra power.
And a more recent result in that field,
which is connected to quantum computing is,
or at least quantum information process,
things like teleportation,
is that if instead of just one merlin,
you have two of them,
and they are quantum merlins,
Arthur is still classical
and still limited in polynomial real time,
but the quantum merlins are entangled,
but not allowed to talk to each other.
So Arthur can ask these two entangled merlins
questions that will trick them up
if they try to lie.
especially because he asked them separate questions.
And their entanglement will help them cooperate to, in some ways,
but not well enough to fool Arthur.
And the result that was proven about six years ago was that in this situation,
these Merlins can convince Arthur of the halting of any touring machine.
In other words, that any kind of computation that might take,
you have no idea how long it would take.
For example, the most, sort of the simplest one is there's an outstanding conjecture in mathematics called Go-Box conjecture, which says that every even number besides two is the sum of two primes.
Now, you could go testing that forever, but no, they haven't found a proof of it, nor, of course, an example of an even number that can't be made by adding two primes.
Now, in this scenario, if there is a negative answer to Goldbox conjecture, in other words, if it's false, two quantum
provers could prove it to Arthur in a very limited amount of time with a proof that Arthur could
actually believe.
Now, the subtle interesting feature of this, or one of them, is that suppose,
that Goldbox conjecture is true, and that, in fact, if you started looking for a counter example,
you'd never find it. We'd say, well, these two quantum provers, they're infinitely wise, so they
already know the answer to that. Can't they just tell Arthur? Yeah, the answer is no. There is no
counter example to go old over the conjecture. No, because they can tell, they can convince Arthur if the
answer is that there is a counter example, but they, they can tell, they can convince Arthur if the answer is a counterexample,
but they can't convince them that there isn't
because they know the answer to the holding problem
but they're unreliable.
So if they tell them the answer is no,
that doesn't enable them to believe that it's no.
So it's a very subtle thing,
but what it says is that taking the analogy
farther back into regular everyday life,
is if you think
that your relation to an artificial intelligence
is like Arthur's to Merlin,
you shouldn't trust what it says.
but you should trust its ability to help you convince you of something that is true
because you just have to learn to ask it questions in the right way.
And I think that's the way we should approach artificial intelligences is to say,
we can't trust them, but they can help us because we can figure out how to ask them questions
where if they're either telling us the truth or we'll catch them at line.
And let me add that the invention of indirective proofs was awarded the Turing Award in 2012 to Silvio Michalien and Sheffi Goldwasser.
Yes, yes.
Although it was also invented independently by Laszlo Bavai, who did not share a Turing Award in 2012.
Well, now, yeah.
But because the Turing Award was also about the cryptographic applications.
Yeah.
So, well, the IPMP space was a little immersed.
earlier than that, right?
Wasn't that Shemeter or something?
Yeah, so anyway, this is a very hot topic in theory.
It had to be after that.
No, IP equals P-Space had to be afterwards.
It had to be invented.
Yeah.
But I'm not hearing which order
the touring award was given though.
Anyway, it got at least one touring award.
Yeah.
And the newer work may get another one eventually.
Oh, yeah.
Yeah.
I'm sure, yes.
So I think that's an optimistic reason, is to say, look, the machines are taking over actually the less important part of our job, and our job is to learn how to be good authors and not be fooled by these machines, even though we're being enormously helped by them.
I don't know if either of you are thoughtful around sci-fi, certainly in the space you operate in, you must have to think about such things.
But when you were telling that story, it immediately made me think of the Harry Mudd episode of Star Trek when Captain Kirk says everything Harry tells you is a lie, no matter what, everything he says is a lie.
And then he says, I'm lying.
And then the android can't reconcile the statement that he's lying is a lie.
So he's telling the truth, and then he explodes.
So in that case, the humans made, they got around the artificial intelligence by being smarter and using the liars.
paradox. Right. Well, my granddaughter's version of that is, how would Pinocchio react if you
ask him if his nose was about to get longer? Oh, that's a good one. Well, thank you both for giving
me so much of your time. You're very generous. I want to thank you both, Charles H. Bennett and
And Jill Brassar.
The...
Oh, he probably...
He hasn't...
You have a middle initial, too, right?
Me?
You?
No.
No.
Okay.
I put...
I did my research.
A stickler about the H.
Because Charles and Bennett are very common names, and there are a fair number of
other times Charles Bennett scientists.
No, understood.
I respect the middle initial, Charles H. Bennett.
And we have been chatting with Charlie H. Bennett and J. Bissar,
the Allen...
Turing Award honorees.
Alan M. Turing.
That's good, touche.
Touche.
For foundational
contributions to quantum information
science. Thank you both so much.
Thank you, Scott. It was a pleasure of talking to you.
Yes.
Bye, bye.
ACM Bytecast is a production of the Association
for Computing Machinery's Practitioner Board.
To learn more about ACM and its activities,
visit acm.org.
For more information about this,
and other episodes, please do visit our website at learning.acm.org slash bitecast. That's B-Y-T-E-C-A-S-T. Learning.acm.org
slash bitecast.
