Keynote Talk #1 (Turing Lecture)
Cassandra No Longer? Privacy in a Quantum World
–, November 16, 2026
Prof. Gilles Brassard
Université de Montréal
Abstract
According to Greek mythology (and Homer’s Iliad), Cassandra is described as the comeliest daughter Priam, King of Troy, and even a peer of Aphrodite. She was given by Apollo the gift of uttering true prophecies, but cursed so that she would never be believed. Had her father Priam taken heed of her warnings, not only Troy may not have fallen, but the War itself might have been avoided.
In April 1994, I uttered my first prophecy in the conclusions of my paper Oracle quantum computing: “A good way of pumping funding into the building of an actual quantum computer would be to find an efficient quantum factoring algorithm!” Within weeks, perhaps days, Peter Shor discovered precisely how to do this. Suddenly, the cryptographic infrastructure on which we had been relying was compromised. As a modern-time Cassandra, I started to preach the need to prepare for this announced disaster. I was even invited by RSA to write a paper with the provocative title of “The impending demise of RSA?” for their newsletter RSA Laboratories CryptoBytes as early as 1995 (it was their only condition that I add this question mark to the title of my paper!). Nevertheless, Cassandra being Cassandra, almost no one paid attention. After all, it was obvious that quantum computers were science fiction at best.
Time passed and people are no longer laughing: extraordinary technological progress has occurred at an ever increasing pace in the past few years. Nobody can doubt anymore that quantum computers capable of running Shor’s algorithm will become a reality (if not already up and running in some secret laboratory). Not only will this wreak havoc on the future of secret communications, but also on the past. Indeed, nothing prevents opponents from recording currently undecipherable Internet traffic. When a quantum computer becomes available, they can decrypt it retroactively. Said bluntly, everything you ever confided to the Internet with a false feeling of security will become an open book. This is known as the “Harvest now and decrypt later” paradigm. The past is lost and nothing can be done about it. All you can hope for is to save the future.
My prophecies are now taken seriously, and therefore it would seem that I am Cassandra no longer. Not so fast! The most popular attempt for securing the future of communications is to develop (and implement) alternative classical key establishment methods that would withstand the onslaught of a quantum computer. This is known as Post-quantum cryptography (PQC). But alas, no mathematical tools are known to prove the safety of those techniques. One reason for trusting RSA before the discovery of Shor’s algorithm was that it is based on a century-old problem: the presumed difficulty of factoring. But the new techniques are based on wishful thinking even more than before. And now that Cassandra (me!) is back trying to warn the world that blind faith in PQC would be ill-advised, “she” is again not taken very seriously. Hence the question mark in the title of this Turing Lecture. :-)
But no worry, quantum cryptography is here to come to the rescue (at least for secure communications). As the late Asher Peres once said, “The quantum taketh away and the quantum giveth back”! A full version of this Turing Lecture will appear in the Communications of the ACM.
Biography
Professor of computer science at the Université de Montréal since 1979, Gilles Brassard laid the foundations of quantum cryptography at a time when nobody could have predicted that the quantum information revolution would usher in a multi-billion-dollar industry, much less that the ACM would grant him and Charles H. Bennett the Turing Award forty-four years after rejecting their first paper on this topic. They are also among the inventors of quantum teleportation. A Fellow of the Royal Society of London, Officer of the Order of Canada and Ordre national du Québec, his accolades include the Wolf Prize in Physics, the Micius Quantum Prize, the BBVA Foundation Frontiers of Knowledge Award in Basic Sciences and the Breakthrough Prize in Fundamental Physics, in addition to the Turing Award. He has been granted honorary doctorates from ETH Zürich, the University of Ottawa, Università della Svizzera italiana in Lugano, and the University of Waterloo.