Firewalls From Double Purity^{1}^{1}1This article is based on a seminar given at the CERN Workshop on Black Hole Horizons and Quantum Information, in March 2013. Video is available at http://cds.cern.ch/record/1532382.
Abstract
The firewall paradox is often presented as arising from double entanglement, but I argue that more generally the paradox is double purity. Nearhorizon modes are purified by the interior, in the infalling vacuum. Hence they cannot also be pure alone, or in combination with any third system, as demanded by unitarity. This conflict arises independently of the Page time, for entangled and for pure states. It implies that identifications of Hilbert spaces cannot resolve the paradox.
Traditional complementarity requires the unitary identification of infalling matter with a scrambled subsystem of the Hawking radiation. Extending this map to the infalling vacuum overdetermines the outstate. More general complementarity maps (“”, “ER EPR”) founder when the nearhorizon zone is pure. I argue that purezone states span the microcanonical ensemble, and that this suffices to make the horizon a special place.
I advocate that the ability to detect the horizon locally, rather than the degree or probability of violence, is what makes firewalls problematic. Conversely, if the production of matter at the horizon can be dynamically understood and shown to be consistent, then firewalls do not constitute a violation of the equivalence principle.
Notation
Most variables will be defined in the text. Here is a list of key definitions:
a minable mode in the nearhorizon region (the “zone”);  

also, the associated annihilation operator  
its purification inside the black hole, in the infalling vacuum  
the Hilbert space of  
the collection of all modes minable at the time  
a bipartite system  
its Hilbert space  
the von Neumann entropy of :  
the complement of the subsystem in  
its Hilbert space 
1 Introduction
Unitarity and the equivalence principle—the central principles of quantum mechanics and of general relativity—come into sharp conflict at the horizon of a black hole. Classically, a black hole formed by collapse quickly evolves to the vacuum Kerr solution. In particular, the neighborhood of the horizon is in the vacuum; intuitively, this is because any matter would rapidly fall into the black hole. The vacuum state at the horizon implies that the Hawking radiation is in a mixed state Haw76a : information is lost.
From the viewpoint of quantum mechanics, the Hawking radiation is the outstate of an Smatrix computed by a path integral. If the instate was pure, then unitarity demands that the outstate is pure. The validity of this viewpoint is closely related to the consistency of black hole thermodynamics: the BekensteinHawking entropy Bek72 allows a generalized second law to operate. (The apparent validity of universal entropy bounds Bek81 ; Cas08 ; Tho93 ; Sus95 ; CEB1 suggests that the generalized second law does indeed hold FMW .) But if no entropy can be lost into a black hole, then it would be surprising if information could be lost. Finally, the AdS/CFT correspondence Mal97 reduces the computation of the gravitational Smatrix to manifestly unitary evolution in welldefined quantum theory. Thus, the evidence for unitarity is strong.
Black hole complementarity Pre92 ; SusTho93 ; SteTho94 was an attempt to reconcile the infalling vacuum with unitarity, by exploiting the fact that certain spacelike related operators in the interior and exterior cannot be accessed by any single observer, allowing their identification. But this appears to fail AMPS : in the theory of the infalling observer alone, unitarity and the validity of effective field theory outside the horizon imply that the horizon cannot be in the vacuum state.^{2}^{2}2See AMPSS for an extensive list of subsequent work. Precursors include Sor97 ; Bra09V1 ; Mat09 ; Gid11 ; Gid12 ; GidShi12 . Ref. Sus13 offers a clear exposition of the relevant concepts from quantum information theory.
Firewalls from Double Entanglement
To demonstrate this problem, Almheiri, Marolf, Polchinski, and Sully (AMPS) considered “old” black holes that had lost more than half of their original area. Assuming unitarity, the “late” radiation that these black holes will decay into is generically highly entangled with the “early” radiation that has already been emitted. In particular, modes in the nearhorizon zone of the old black hole are entangled with the early radiation, since they can be mined and thus form a subsystem of the late radiation. The zone consists of modes that are far enough from the horizon to be under semiclassical control, but closer than a Schwarzschild radius. In the infalling vacuum, these modes would be entangled with modes inside the black hole. But this would contradict the monogamy of the entanglement, a general property of quantum mechanics. Hence, they cannot be in the vacuum state. Mode by mode, this implies an energy density controlled by the fundamental cutoff, at the horizon. This is the firewall.
AMPS’s elegant exploitation of double entanglement has become deeply embedded in the literature, perhaps to the point of obscuring the generality of the conflict. In fact, the zone need not be entangled with the early radiation or with anything else. Suppose instead that the outstate factorizes into a product state of zone and other degrees of freedom. Then the firewall is even more obvious: since the zone is in a pure state all by itself, it cannot also form a pure entangled state with the interior. In fact, no exact factorization is needed: if the entanglement of the zone with the early Hawking radiation is less than thermal, then the state of the zone by itself is incompatible with its being a subsystem of the infalling vacuum.
The focus on double entanglement has encouraged an optimistic view of the role that complementarity can play in eliminating firewalls. Suppose that not only the infalling matter, but also the vacuous interior regions are identified with scrambled subspaces of the Hawking radiation. For highly entangled states of the zone with the “early” radiation, this would appear to circumvent the AMPS argument. After all, the vacuum, too, is a highly entangled state. A suitable choice of map should allow the reconstruction of the vacuum at the horizon. This strategy is variously called “”, or “ER EPR”; or in the notation of the present paper, . Recent proposals include VerVer12 ; PapRaj12 ; Sus13 ; NomVar13 ; VerVer13a ; VerVer13b ; MalSus13 . In all cases, , the exterior purification of the zone modes , is identified with , the interior partner modes of in the infalling vacuum. Thus, the inconsistent double entanglement of is reduced to a consistent, single entanglement.
However, none of the above arguments apply if the state of the zone and other exterior systems factorizes. More generally they do not apply if the entropy of the zone is small compared to the thermal entropy. But a complete basis of the microcanonical ensemble of a black hole can be constructed from such states, each of which trivially has a firewall. This alone creates a conflict with the equivalence principle.
Outline and Summary
The purpose of this paper is twofold: first, to examine what complementarity can and cannot achieve; and second, to argue that resolutions that exploit entanglement necessarily fall short, because firewalls arise independently of the degree of entanglement between the near horizon zone and other exterior systems. The arguments presented here will make no reference to such entanglement. Hence they apply equally to young and to old black holes, and equally to black holes in entangled and in pure states.^{3}^{3}3This article largely follows Bou13 . Since then, interesting papers have appeared which have some overlap and some differences. Ref. MarPol13 considers unentangled states in the powerful context of AdS/CFT; Ref. Cho13 examines the D1D5 system to argue that a microcanonical ensemble exists for black holes with positive specific heat. The arguments presented here do not rely on gauge gravity duality and do not restrict to nearextremal or large AdS black holes. Ref. AMPSS also speculates that firewalls are continuously produced at the horizon (though somewhat inside).
In light of the firewall paradox, it is important to reconsider the need for complementarity, to identify its role, and to understand its limitations. It is instructive to begin with the naive viewpoint that the interior and exterior have independent Hilbert spaces. In Sec. 2, I show that firewalls arise from a conflict between the entangled purity of the vacuum with the purity of the outstate, regardless of the amount of entanglement between any of the exterior subsystems. In the remainder of the paper, I argue that complementarity cannot mitigate this basic conflict sufficiently to reconcile unitarity with the equivalence principle.
Some form of complementarity is clearly required by unitarity, with or without firewalls. A collapsing star cannot hit a firewall at the event horizon: by causality, a firewall can form only later. Inside the black hole, the star carries the same information as the outgoing Hawking radiation at spacelike separation, in apparent violation of the nocloning theorem WooZur82 . However, no observer can see both copies SusTho93b . Strictly, this does not mean that one has to identify the two Hilbert spaces. (One could merely note that in any single observer’s description, only one copy appears.) But it is consistent to do so.
The simplest implementation of complementarity is a unitary map of the Hilbert space of any infalling matter to a (possibly scrambled) subsystem of the Hawking radiation. This is linear, and it is causal, assuming that the information only appears in the radiation once it is too late to reunite it with the infalling matter HayPre07 . In Sec. 3, I note that if a unitary complementarity map is applied to the infalling vacuum instead of the infalling matter, then it becomes inconsistent with unitarity of the Smatrix, because the vacuum is a unique state. Hence, a unitary identification of the interior vacuum regions with the Hawking radiation does not resolve the conflict between unitarity of the Smatrix and the equivalence principle.
This has motivated “stronger” versions of complementarity, in which the complementarity map is not required to be unitary. Instead, it is allowed to depend on the outstate, so that the infalling vacuum is recovered independently of the outstate. This could lead to problems with causality, since in many situations the image of the infalling vacuum would have to be present outside prior to infall. (The outside copy is hard to access computationally in Haartypical states HarHay13 , but the relevance of this obstruction remains controversial Bou13 ; AMPSS .)
In Sec. 4, I will focus on a different problem: no form of complementarity can restore the infalling vacuum for states in which the zone is in a pure state. I argue that the statistical interpretation of black hole thermodynamics guarantees that such states form a complete basis for the microcanonical ensemble. I then argue that this is sufficient to establish a violation of the equivalence principle, as the presence of a firewall in a complete basis differs in several respects from acceptable particle detections in curved space. The horizon is a special place.
Two Conclusions
Firewalls appear to violate the equivalence principle, in its formulation as the following statement: The vacuum, on scales smaller than the curvature scale, has the same properties everywhere. Violating the equivalence principle is a serious problem. But it is, in my view, the only problem. I emphasize this because it has two important implications, which appear not to be universally accepted:

There is no point in pursuing approaches which merely seek to make the horizon less “violent”, or to make infall possible in some way for most observers, but in which it still is possible for a local observer to notice the event horizon. There is no principle of nonviolence in Nature. But if the horizon is a special place—if crossing it can be locally detected with sufficient probability—then no matter how harmless the crossing, the equivalence principle is lost, and with it the foundation of general relativity.
This criterion is quite selective. It excludes any model that fails to address firewalls in product states: as I argue in Sec. 4, the presence of firewalls in these states alone is already incompatible with the properties of the adiabatic vacuum.
Another example, which will not be discussed in the main portion of the paper, are nonlocal modifications of effective field theory. They must selectively involve the short distance modes just inside and outside the horizon, which form the most violent part of the firewall. But if field theory is mainly modified very close to the horizon, then the horizon becomes a special place because detectors behave differently there.^{4}^{4}4For this reason, the validity of effective field theory could be eliminated from the assumptions made by AMPS, if the needlessly weak “absence of drama” assumption is replaced by the stronger but essential requirement that the horizon must not be a special place. (In Gid12 this problem manifests itself as a failure of the vacuum to produce the correct Unruh effect. An observer hovering near the horizon will detect considerable excess above the thermal flux Unr76 that the same detector would see in any other lowcurvature region, at the same acceleration.)

If the horizon is not in the vacuum, then firewalls are perfectly acceptable. The equivalence principle is not violated when I bump into a wall: there is matter there, which makes it a special place. This is obvious; the real problem is to understand how deviations from the vacuum can survive near the horizon of a black hole. Why don’t they just fall in? What must be happening is that the firewall is continuously produced, from transplanckian modes near the horizon that are getting stretched into observable size by the exponential redshift. Unlike what we usually assume, those modes apparently do not emerge in the vacuum state.
In cosmology, new semiclassical modes enter in two ways. As we get older, our past lightcone encompasses ever new regions. Their state is determined by initial conditions, which evidently constrain ultraviolet modes to be in the vacuum. And as the universe expands, regions that were already in our past lightcone increase in volume. Conservation of the stress tensor ensures that stretched unexcited modes remain in the vacuum.
However, near a Killing horizon after the scrambling time , neither constraint applies. Our past lightcone has disconnected boundary components near every black hole, but no new information enters from the distant past as the area of the component becomes nearly independent of time. Meanwhile, the energy cost of any local excitation at the boundary is arbitrarily redshifted. Apparently the fields exploit this freedom to emerge in a nonvacuum state determined by the most recent infalling matter or infalling zone modes. It will be important to understand how this process is consistent with Lorentzinvariance, and how it reproduces the coarsegrained features of black hole thermodynamics.^{5}^{5}5It will also be interesting to investigate its role in cosmology, particularly in the context of the measure problem, where a firewall might explain otherwise puzzling features BouFre10c .
To summarize, a fundamental principle cannot break down on occasion, without being completely undermined. But the case for firewalls is sound. Hence, what must break down is not the equivalence principle but the adiabatic vacuum. This would allow substantial new physics in particular settings, such as finite Killing horizons, while preserving general relativity.
2 Firewalls from Double Purity
In this section I give a general argument in favor of firewalls that does not assume maximal entanglement of subsystems of the Hawking radiation. Hence it does not depend on whether the black hole is young or old.
I will exploit that modes outside the black hole must form an entangled pure state with interior degrees of freedom, if an infalling observer is to find a vacuum at the horizon. This contradicts the purity of the Smatrix outstate, independently of whether the mode in question is pure or entangled with other portions of the Hawking radiation.
I will not appeal to complementarity in this section. But in the following sections I will examine various forms complementarity, in light of the present formulation of the paradox; and I will find that firewalls are still required for unitarity. Hedging the firewall argument against objections that ultimately fall short tends to obscure the origin of the problem. Therefore, it is instructive to begin with the most straightforward setting, with all systems treated as distinct.
2.1 Quantum Mechanics Argument
The argument is general at the level of quantum mechanics, and I will state it abstractly before applying it to the black hole. Consider a bipartite system in a pure, entangled (but not necessarily maximally entangled) state:
(1) 
Then there cannot exist a third system , entirely distinct from , such that the state of is pure; for otherwise we would have
(2) 
and the strong subadditivity of the entanglement entropy LieRus73 ,
(3) 
would be violated.
Conversely, it follows for any , : if the state of is pure (entangled or not), then Eq. (1) cannot hold, i.e., cannot form an entangled (maximally or not) pure state with some other system .^{6}^{6}6If were maximally entangled with then the stronger conclusion would obtain that cannot even be classically correlated with . But this conclusion is nowhere needed in the firewall argument.
Below, the role of will be played by the infalling vacuum; the role of by the final outstate (the entire Hawking radiation). The inference
(4) 
states that the infalling vacuum implies information loss. The equivalent inference
(5) 
states that unitarity implies a firewall.
2.2 Application to Black Holes
I will now explain how the abstract subsystems and assumptions above are related to physical systems and conditions in a black hole spacetime. An important physical ingredient that was necessarily absent in the abstract argument above is minability of a large class of modes near the horizon. These are the modes that form the firewall. I will pay special attention to the role of mining.
Consider a black hole of radius ,^{7}^{7}7Planck units are used throughout. formed from a pure state . Let be a mode with support strictly outside the horizon, at a time much greater than after the most recent infall of matter into the black hole. To be physical, we can work with wavepackets, which can be constructed from the standard exterior mode set. The modes of greatest relevance for the firewall argument have Killing frequency of order the Hawking temperature, ; they are localized in the near horizon zone (within ), at a proper distance from the horizon not much greater than their characteristic proper size. All scales are assumed much greater than the Planck length, so that effective field theory should describe the mode to good approximation.
2.2.1 The Minable Zone as a Subsystem of the Final State
Modes of this type can be mined UnrWal82 : if they are extracted from the zone, the mass of the black hole decreases and the energy of matter far from the black hole increases. Hence, the mode must be considered a subsystem of the final state, independently of whether it is actually probed:
(6) 
Here, denotes the Hilbert space for the outstate of the Smatrix, and denotes the Hilbert space of the system that complements in the final state. The Hilbert space is spanned, e.g., by the eigenstates of occupation number, .
Because the mode can be mined, it is irrelevant whether it is outgoing or not, nor does it matter whether it is an swave or has angular momentum. I assume only that effective field theory is valid outside the horizon, so that (and, if necessary, the mining equipment) can be evolved a large distance from the black hole, to null infinity, where the outstate is exactly defined. By unitarity, the outstate is pure, so its von Neumann entropy vanishes:
(7) 
2.2.2 The Minable Zone as a Subsystem of the Infalling Vacuum
The mode is also a subsystem of the quantum field in a neighborhood of the horizon that includes comparable portions of the interior and the exterior of the black hole. We can choose much larger than the distance of from the horizon but much smaller than the black hole radius . To be concrete, let be an infalling geodesic (“Alice”) and let be events at proper time () before and after the geodesic crosses the black hole horizon. We can define as the causal diamond , i.e., the points that can be causally probed by experiments that start after and end before . I will sometimes refer to the time when Alice falls in, which can be defined as the Schwarzschild time of to adequate precision. None of these definitions require Alice to fall freely from very far away, just from farther than the mode of interest.
Since no matter has entered the black hole for a time greater than , by the nohair theorem the region should be free of matter. By the adiabatic theorem, the production of particles localized to is exponentially suppressed in . Hence an infalling observer should see the Minkowski vacuum on the scale of :^{8}^{8}8In fact, the state of is highly entangled with its complement through ultraviolet modes near its boundary. But same type of entanglement would also be present for a causal diamond in exact Minkowski space. Since is much larger than the support of , this entanglement is dominated by modes orthogonal to and is irrelevant for this discussion.
(8) 
The Minkowski vacuum can be written in Unruh form Unr76 ,
(9) 
where and is a normalization factor. Here () are creation operators for Rindler modes of frequency on the left (right). Transverse momenta have been suppressed for ease of notation. Let us consider a particular right Rindler mode with frequency . Evaluating the exponential in Eq. (9) for this frequency one finds:
(10) 
Tracing over the complement of trivially gives the pure state in the parentheses: the right mode is entangled with and purified by the left mode . Tracing also over , one obtains a thermal state . If , this state has von Neumann entropy of order unity:
(11) 
The exact Rindler mode considered here has support in the entire right Rindler wedge, and in the Minkowski vacuum, its purification lives only on the left. But consider an approximately stationary wavepacket of characteristic frequency and size , localized strictly in the right wedge at . In the state the purification of comes from modes with support both on the left and on the right. But the key point remains that in the Minkowski vacuum, the state of is mixed and cannot be purified without accessing the left wedge. Moreover, by increasing at fixed , the frequency can be made very sharp, so . It will make no difference below whether the state of in the infalling vacuum is pure or just nearly pure (), so for simplicity I will write for wavepackets. Moreover, if the characteristic Rindler frequency of the packet is of order the Unruh temperature, then Eq. (11) continues to hold at the stated accuracy. To summarize, for the wavepacket one has
(12) 
Since Minkowski space is a good approximation for the horizon neighborhood , and since is well localized within , Eq. (12) also follows in the case of a wave packet mode in the nearhorizon zone of a black hole. With the appropriate renormalization (unit Killing vector at infinity), the characteristic frequency of the relevant modes is order the Hawking temperature, . The purification is the “partner mode” in the black hole interior.
With , , and , we see that unitarity, Eq. (7), and the infalling vacuum, Eq. (12), correspond to Eqs. (2) and (1), and thus are mutually incompatible. If we insist on the infalling vacuum, then Eq. (7) fails substantially: each Hawking particle carries entropy of order unity, and not a single one can be purified by any other part of the Hawking radiation; so the information about the initial state is lost. Conversely, if we insist on unitarity, then Eq. (12) fails substantially. The argument applies to any mode in the near horizon zone, down to a Planck scale cutoff from the horizon. Thus all modes spanning the horizon are in an excited state at short distances. This is the firewall.
2.3 Discussion: the Dual Role of Minability
As advertised, this argument has made no assumptions about the age of the black hole, or about the degree of entanglement of the minable zone with any other exterior degrees of freedom. In this respect, it is significantly more general than earlier arguments AMPS . It implies a firewall after the scrambling time, , when the exterior metric has reached its asymptotic form demanded by the no hair theorem, and the apparent horizon nearly coincides with the event horizon that would obtain if no other matter ever enters. If additional matter enters, a new firewall must form a (new) scrambling time later at the new apparent horizon.
The above argument makes more extensive use of the properties of minable modes than AMPS . Here I will aim to address some potential objections and to clarify the role of minability in the firewall argument.

Suppose that there existed some yet unknown, fundamental obstruction to mining. Then modes with high angular momentum would almost inevitably fall back into the black hole, because of the angular momentum barrier. But this would not fully resolve the firewall paradox. Modes with low angular momentum escape from the zone on their own account, with probability of order unity. These modes form spherical wavepackets that are sharply localized in the radial direction and close to the horizon, with characteristic size and distance . Their detection by a local observer is only powerlaw suppressed AMPS in the detector size over . This alone marks the horizon as a special place. The adiabatic vacuum requires exponential suppression in , with no enhancement for wavepackets close to the horizon.
Because they cannot fully eliminate firewalls, I will not investigate obstructions to mining here; I assume there are none.

The minable zone satisfies two important conditions: that the minable modes are a thermally entangled subsystem of the infalling vacuum, and second, that their extraction decreases the entropy of the black hole. If any one of these conditions did not hold, the double purity conflict could not arise. Without the first condition, the entropy of would not need to be ; and to the extent that did have entropy, its purification would not be concentrated inside the black hole. Without the second condition, one could argue that only became part of the outstate as a result of actually probing it. I will first discuss their interplay in estabilishing the firewall. Then I will provide two examples that illustrate how at least one of these conditions breaks down in regions other than the Killing horizon of a black hole, where there must not be a firewall.

When the minable zone is probed, then both conditions are satisfied. The first condition plays a role in ensuring the second. Because the vacuum is highly entangled, the probability of creating a partner inside the black hole (upon detection of the outside mode) will be of order unity. It can be made arbitrarily close to unity by measuring a wavepacket with sharp Schwarzschild frequency.
Because of the spacelike character of the Killing vector field behind the horizon, the production of the partner mode decreases the black hole mass, by an amount equal to the mass of the detected particle. Hence, the energy at infinity can be conserved without draining energy from the detector or from the mechanism that holds it in place. The black hole pays for the energy of the mined particle.

The first condition makes it important to distinguish the minable zone from the geometric nearhorizon zone, defined as all wavepackets with support mainly in the region between and . The minable modes also have support mainly in this region. But in addition, they have proper wavelength comparable to their proper distance from the horizon, and they do not have much support outside the angular momentum barrier, which will be closer than for modes with large angular momentum.
For example, suppose we measure a wave packet of size localized just inside . By the ReehSchlieder theorem, this has some probability of creating a particle behind the black hole horizon. But because such modes have almost no overlap with the minable modes, this probability will be exponentially small. More likely, it will create another particle that is also outside the black hole. The energy for any new particles inside or outside the detector comes from the detector stirring up the vacuum, not from the black hole. This process is trivial and does not conflict with the infalling vacuum; it is like creating any other entangled pair far from the black hole. Hence there is no firewall at , or anywhere far from the black hole.

The second condition is also essential. Consider, for example, the vacuum near the portion of the event horizon inside a collapsing null shell. This spacetime region is exactly flat, and by causality there must not be a firewall. However, an accelerated observer could detect a Rindler mode just outside the event horizon and transport this particle through the shell to future infinity. In the outstate this particle must be purified by the rest of the Hawking radiation, apparently implying a firewall in violation of causality.
But this process does not mine; it adds energy to the black hole. Mining is possible once the event horizon becomes a Killing horizon, which happens rapidly after collapse or infall but can take up to a scrambling time, . The event horizon inside the shell is not a Killing horizon with respect to the Killing vector field at infinity. Hence the partner mode created behind the horizon by the detection UnrWal84 can increase the energy of the black hole that forms, compared to what it would have been if no particle had been detected. (Less energy is retained in matter that stays outside the black hole, because of the backreaction that lowers the kinetic energy of the detector.)
As a result there will be more Hawking radiation than if the experiment had not been performed. The detector and exterior environment are entangled with the interior mode, but their purification may reside in the additional Hilbert space. Therefore it is not possible to argue that the exterior mode would have been purified by the smaller Hawking cloud that would have formed if the experiment had not been performed. Hence it is consistent to declare that the region was in the vacuum state prior to the experiment.
The same discussion applies when a black hole grows to larger size. For example, consider a spherical null shell of mass collapsing around a black hole of much smaller mass . The vacuum near the apparent horizon inside the shell can be mined to large distances compared to , so the small black hole has a firewall. But the vacuum near the event horizon inside the shell cannot be mined; so a new, larger firewall at need not form until later, on the horizon portion outside of the shell.

Returning to the case of successful mining, it is not crucial that the expectation value of the black hole energy decreases by the full energy of the detected particle. In an unclean experiment, the apparatus may add a tiny amount of energy both to the mined particle and to the outside of the black hole. The latter energy may fall into the black hole and partially cancel the energy decrease due to mining. I am merely assuming that mining can be accomplished while keeping these effects small. Then the mined mode cannot be purified by the small excitation that fell into the black hole but can be nearly purified () by some scrambled subsystem of the Hawking radiation . Since little energy was added, this subsystem would have been emitted in any case. This implies that independently of whether the experiment is actually carried out. Hence, there was already a firewall at the horizon before the experiment.

The previous observation is important, because the exterior Rindler or Schwarzschild modes formally reach all the way to the geometric event horizon. But semiclassical mining can only reach to the stretched horizon, of order a Planck length outside the geometric horizon, where the local temperature experienced by mining equipment would reach the Planck temperature. However, we can take the wavepackets to have support outside of this region. This will not significantly alter them unless they mainly had support near the stretched horizon to start with. The point is that the characteristic size of the wavepackets depends on the angular momentum but the size of the region that is semiclassically excluded depends on a fixed cutoff. This will also be important in Sec. 4.3.

On a final note, the speedup of the evaporation process that can be achieved with mining Bro12 plays no role the firewall argument. What matters is that any minable mode could, in principle, be accessed; and that the energy of the black hole is decreased by its extraction. This implies that its quantum state is determined by the assumed unitarity of the Smatrix. It is irrelevant whether it is actually mined, since in quantum mechanics the state of a system prior to a measurement or coherent manipulation is independent of whether the procedure is carried out or not.
3 Simple Complementarity vs. Uniqueness of the Vacuum
In this section, I will consider black hole complementarity Pre92 ; SusTho93 , in its simplest form sufficient for evading the xeroxing paradox. I will show that it does not invalidate the argument for firewalls in the previous section. Firewalls remain necessary. This is due to the uniqueness of the infalling vacuum, . This obstruction was noted in Bou12c (see also AveCho12 ; Bou13 ; Cho13 ); I expand on it here.
3.1 Quantum Mechanics Argument
Again I begin with a general argument at the level of quantum mechanics. In Sec. 2.1, we assumed that and are distinct. Let us now drop this assumption and instead identify with via a unitary map:
(13) 
This is assumption (a), corresponding to black hole complementarity. If and are the same Hilbert space, then obviously the purity of is not only consistent with the purity of but in fact equivalent to it.
However, suppose that we now demand that (b) is in a unique quantum state . (This corresponds to the infalling vacuum of a black hole formed from collapse, after a scrambling time.) Finally, we also demand that (c) can be in more than one distinct quantum state . (This would be required by unitarity, since a black hole can be formed from more than one distinct state.) But obviously, (a), (b), and (c) cannot all be true. I will now apply this reasoning to the black hole in more detail.
3.2 Application to Black Holes
Whether or not firewalls form after collapse, unitarity gives rise to the wellknown xeroxing problem SusTho93b . The same pure state is apparently present both inside the black hole and in the Hawking radiation, at the same global time. But arguably, the black hole retains accreted information for a scrambling time HayPre07 . Then no observer can access both systems simultaneously. So it is consistent to identify the Hilbert space of the matter inside the black hole with the Hilbert space of the Hawking radiation.
In order to address the firewall paradox as exhibited in the previous section, one would need to demand an identification of the interior (assumed to exist) with the Hawking radiation even at times when no matter enters the black hole. This puts too great a burden on the complementarity map, as I will now show.
For any infall time , I demand that an interior exists and that its modes can be identified with a subsystem of :
(14) 
I assume that the map between states in and is linear and unitary (i.e., it is invertible and preserves the inner product between pairs of states in ). The unitarity of the map ensures that the unitarity of the local evolution of the collapsing matter inside the black hole is consistent with the unitarity of the Smatrix. (In general, one expects that is highly scrambled in , i.e., a complicated unitary would need to be applied to the physical carriers of the outstate in order to display as a physical subsystem.)
There is a new difficulty, however. Unitarity and effective field theory outside the horizon imply that every minable zone mode involved in the infalling vacuum is part of the outstate Hilbert space . Hence .^{9}^{9}9The prime indicates that this is not a direct product since there will be overlaps between the degrees of freedom present in the zone at different times. For example, for small , . Moreover, unitarity requires zone degrees of freedom to be recycled even over larger timescales. Conversely, every Hawking radiation quantum arriving at future null infinity passed through the zone at an earlier time, when it was trivially minable, so . Therefore
(15) 
This result does not mean, nor do I assume, that all of is accessible to an exterior observer at a particular single time while the black hole is still present. Similarly, the identification (14) only implies that the interior mode is part of the out state. It does not mean, nor will I assume, that is minable from the zone at any one given time during the evaporation process.
In the infalling vacuum, the zone mode and its interior partner are in the particular state
(16) 
But by Eqs. (14) and (15), we have . By Eq. (15), the collection of all modes spans , so the collection of pairs only introduces redundancy and still spans . Mode by mode, Eq. (16) defines a unique state in . This outstate would be pure, unlike in Hawking’s calculation. But it would be independent of the instate, in violation of unitarity. Information would be lost.
Conversely, if we insist that the out state is a generic state , then with the identification (14), the state of every mode pair will generically be approximately orthogonal to (16). This implies an deviation from the infalling vacuum. Mode by mode, the probability of seeing no particles differs from unity by an order one quantity. There are independent minable modes in the semiclassical regime; and this number is dominated by wavepackets with wavelength near the UV cutoff, a distance of order the UV cutoff from the horizon. Hence, the expected number of excited highfrequency modes is , and there is a firewall localized at the horizon.
The vacuum condition, Eq. (16), will not hold for all zone modes during times when matter enters the black hole. But this does not affect the above argument. Consider a black hole that forms from collapse of a star and then evaporates without further absorption of matter. (The standard picture of a harmless black hole horizon is certainly overthrown if firewalls are present in such black holes.) The above argument begins to apply unchanged at a time of order after collapse, when the nohair vacuum configuration should be reached. We may exclude from the Hawking quanta that will have been emitted during the first scrambling time. These quanta can only carry away qubits of information, but the collapsing star can have up to qubits. The above argument then shows that the remaining Hawking radiation also cannot return the information.
More generally, any minable mode that is not actually mined or emitted can be excluded from without invalidating Eq. (15). Hence, the modes occupied by infalling matter can be excluded. Then the above argument refers only to modes for which Eq. (16) can be demanded. Thus, the outstate becomes highly overdetermined, approximately by the entropy of the infalling matter, if we allow vacuum regions to participate in a unitary complementarity map.
3.3 Discussion
I close this section with two comments.
It is sometimes argued that not all states, , associated with a black hole of area can actually be produced. This seems implausible; it would mean that black hole thermodynamics has no standard statistical interpretation, and I argue explicitly against this possibility in Sec. 4.3. But it does not help in any case. Black holes can certainly be formed in many different states. By slowly condensing soft quanta of wavelength comparable to the Schwarzschild radius (“inverse Hawking radiation”), one can produce orthogonal states. Rapid collapse of an initially stationary system allows for . But demanding the infalling vacuum at all times leads to a unique outstate. One could “reserve” a fraction (with or ) of the degrees of freedom in for factors of the form Eq. (16). But all of the Hawking radiation passes through the zone. Even a small fraction of swaves that are firewalls while in the zone constitutes an unacceptable violation of the equivalence principle, since their characteristic size will be much smaller than near the horizon. This is a horizon marker, in violation of the equivalence principle. Deviations from the adiabatic vacuum in quanta of wavelength much less than than the curvature radius must be exponentially suppressed.
It is important to note that complementarity, understood as a unitary map relating the interior to the outstate, is perfectly consistent, if we do not insist on the infalling vacuum except in those places where the existence of a firewall is excluded by causality. This weaker requirement will not overdetermine the outstate. When a system collapses to form a black hole, it enters the interior before the firewall forms; this region must have an image in , by unitarity of the Smatrix. Similarly, if the black hole grows due to accretion, matter enters the interior of the new, larger black hole before hitting the (old) firewall. (Later a new firewall forms at the larger horizon.) The accreted information contains, by unitarity, is also in and so there is a “pullbackpushforward procedure” FreSus04 ; BouSus11 ; Sus12c that establishes a unitary complementarity map between interior and Hawking radiation. The vacuum (i.e., the fact that certain modes were not excited in the infalling matter) can be included in this map, while the pullbackpush forward procedure remains welldefined. However, the procedure becomes illdefined a scrambling time Sus12c after accretion, because the backward evolution out of the black hole would involve transplanckian frequencies. The region between the old firewall and the new event horizon ceases to be accessible, so pullbackpushforward based on the most recent infall does not constrain the state on this part of the horizon, and a unitary complementarity map need not include this region. This is consistent with a new firewall having formed after the scrambling time.
4 Strong Complementarity vs. Linearity
In this section, I argue that simple complementarity (i.e., “pullbackpushforward”, as described in the previous paragraph), cannot be generalized or extended so as to eliminate firewalls. It would seem problematic to relax the unitarity of the complementarity map, since it is then not clear how the map can remain consistent with the unitarity of the Smatrix. And the previous section showed that the map cannot be extended to include the vacuum behind the horizon more than a scrambling time after the most recent accretion. But I will not use either of these arguments here. Instead, I will present evidence that the infalling vacuum cannot be recovered in any case, at the full level of generality required by the equivalence principle, no matter how the map is defined. (As discussed in the introduction, my viewpoint is binary. If the equivalence principle is not fully recovered, then it remains violated. I regard this as the only relevant criterion.)
The most general map one can consider is a nonunitary map from to that takes , for all .^{10}^{10}10The map need not involve all of , and it could depend on . Observers whose infall time differs by more than the scrambling time cannot compare their experiences at the horizon. Hence one could take the viewpoint that the equivalence principle is recovered as long as a map can be found for any one observer, such the horizon is in the vacuum when and where they cross it. Here I grant this flexibility, which is called observer complementarity Bou12cV1 or strong complementarity HarHay13 . I argue that the approach falls short in any case. However, both the total Hawking radiation , and the neighborhood of the horizon contain the minable zone as subsystems. In general, such a map would assign two inconsistent states to ; for example, if factorizes, the state of the zone is pure; yet the state of the zone in the vacuum must be mixed.
If is random with respect to the Haar measure, then with overwhelming probability the state of alone is nearly exactly thermal. I will begin by discussing maps that attempt to exploit this fact, in Sec. 4.1. I will introduce a toy model in Sec. 4.2 to illustrate the issues explicitly. In Sec. 4.3 I argue that while nonthermal states of are Haarrare they are not Boltzmannrare; they span the full microcanonical ensemble. In Sec. 4.4 I argue that this fact alone constitutes a violation of the equivalence principle, independently of the status of thermally entangled states.
4.1 Donkey Map
There do exist states , such that the state of , regarded as a subsystem of , is the same as the thermal state of as a subsystem of the vacuum:
(17) 
In this case a manytoone map can be realized as a map just between and , the purification of in :
(18) 
To distinguish it from the stateindependent and infalltimeindependent unitary map of traditional complementarity, Eq. (14), I will call this construction a donkey map. We will see explicitly in the example below how must depend on the full outstate . Viewed as a map from to , the donkey map is manytoone,^{11}^{11}11This was first criticized in Ref. Bou12c (see also AveCho12 ; Bou13 ). Following, e.g., PapRaj12 ; VerVer12 ; Sus13 ; NomVar13 ; VerVer13a ; VerVer13b ; MalSus13 , some difficulties associated with statedependence were further elaborated in Ref. AMPSS ; MarPol13 . The present nomenclature is inspired by recent discussions VerTalk ; MarPol13 . What I here call a donkey map does not fully represent the content of, nor differentiates between, Refs. PapRaj12 ; VerVer12 ; Sus13 ; NomVar13 ; VerVer13a ; VerVer13b ; MalSus13 . But I argue that none of these proposals can eliminate firewalls in product states. since it always results in the infalling vacuum independently of the outstate.
Eq. (17) is indeed satisfied to high accuracy for Haartypical states Pag93 . Hence, extant arguments have mainly focussed on this case. For example, Ref. AMPS noted that for old enough black holes both systems, and , are semiclassically accessible to the infalling observer; hence it is inconsistent to identify them in any manner. (By contrast, in the conventional complementarity of Sec. 3, the two systems that are identified are not semiclassically accessible to any one observer.) The counterargument that may not be computationally accessible HarHay13 has been questioned in Ref. AMPSS . The issue remains controversial VerVer13a ; VerVer13b ; MalSus13 ; MarPol13 ; Bou13b .
Here I will argue that strong complementarity falls short in any case, for a different reason Bou13 . I focus on the problem noted earlier: can only have one state, so it must be invariant under the map from to . Hence the map can only connect and nontrivially. But if the state of is pure, then by Eq. (3), no identification of with any subspace of can achieve the vacuum. Pure states in form a complete basis of and hence are not Boltzmann suppressed, as acceptable deviations from the adiabatic vacuum must be. Thus, the equivalence principle is violated: the horizon is a special place.
4.2 Two Qubit Example
A simple example will illustrate the donkey map, its structure, and its shortcomings. I model the zone, , as a single qubit . The infalling vacuum is modeled as the EPR state
(19) 
Statedependence of the map
I begin by considering the case where is maximally entangled. For simplicity, I take . (In general may contain additional Hilbert space factors that do not participate in the map or whose participation itself depends on the state .) This toy model and state could represent a young black hole (negligible radiation has been emitted), if we take to be the semiclassically inaccessible Planckian modes near the horizon (assumed to contain precisely half of the degrees of freedom, for simplicity). Or it could be interpreted as a halfevaporated black hole: would represent the Hilbert space of the early Hawking radiation. In this case, we would assume that all of the zone is semiclassically accessible, for simplicity.
Each of the four Bell states that span can be converted to by a map that acts only on . But as the reader can easily verify, for each such state of , the map from to must be chosen a different Pauli matrix:
(20) 
Note that in every state considered above, the accessible mode is in the same state that it has in the vacuum,
(21) 
as required.
Product states
The Bell states in Eq. (20) form a complete basis of , but so do product states. In this case is already pure by itself, so the Hilbert space is empty, and the donkey map cannot defined by Eq. (18). Moreover, any map from to must leave invariant. It can only act on the complement of in , denoted , with Hilbert space factor . Hence, the product structure is preserved, and the vacuum cannot be obtained with any choice:
(22) 
where the states depend on the arbitrary map .
It is worth restating this point. In every state in the above basis, the accessible mode is in a pure state (either or , though of course a different choice could have been made). This state must be preserved: because can be measured before crossing the horizon, all observers must agree on its state. Indeed, the map acts only on . But this means that the neighborhood of the vacuum is also in a product state. The overlap of any product state with the vacuum state, Eq. (19), differs from unity by a term of order unity. Thus the probability for encountering a particle at the horizon is substantial: a firewall.
4.3 Product States Form a Complete Basis
In this subsection I argue that Eq. (22) of the toy model correctly captures a property of the Hilbert space of a black hole: There exists a complete (highly nonunique) basis, such that every basis element is a product state of the zone and any other degrees of freedom that might be associated with the black hole. Because by itself is already pure, every such state has a firewall. A map that identifies the exterior purification of with the interior cannot help since it has no space to act on.
4.3.1 Black Hole Thermodynamics has a Statistical Interpretation
I will assume that black hole thermodynamics Bek72 ; BarCar73 ; Haw75 is valid.^{12}^{12}12This might be questioned if there are firewalls. But the argument for firewalls is by contradiction and so assumes their absence; then black hole thermodynamics stands on a solid footing. In particular, black holes satisfy a first law, Eq. (24), with (for Schwarzschild)
(23) 
Moreover, I assume that black hole thermodynamics has a statistical interpretation, as unitarity demands.^{13}^{13}13Note that this assumption refers only to the black hole as probed by an exterior observer. It does not prejudice what other system the interior modes might be identified with. Thus, I do not assume the “proximity postulate” Sus13 . To be concrete, I assume that black holes share the following standard properties of the canonical and microcanonical ensembles of ordinary thermodynamic objects, such as the air in a sealed room, or a cavity filled with electromagnetic radiation:
Canonical Ensemble
The entropy as a function of energy, , can be macroscopically determined by controlling the temperature, measuring , and integrating
(24) 
The microscopic interpretation is
(25) 
where
(26) 
Here is the probability of finding the system in the state with energy . The Hilbert space in which acts is generally of infinite dimension (e.g., a Fock space). The energy expectation value is
(27) 
Microcanonical Ensemble
The microcanonical ensemble consists of states with energy in a narrow range around . Its density matrix is proportional to the unit matrix:
(28) 
where is the finite dimension of the Hilbert space spanned by these states.
Thermodynamic Limit
In the thermodynamic limit, the entropy of the canonical ensemble is dominated by states of energy , and so agrees with the microcanonical entropy
(29) 
The statistical interpretation implies that canonical and microcanonical ensembles with these properties exist for a black hole. This requires suitable boundary conditions, such as a box Haw76 . Antide Sitter space makes for a good box HawPag83 , but any small enough box will do. The box is needed only to prepare the black hole; the timescale for this may be very long. A firewall for a black hole in a box seems no more acceptable than in any other setting; the equivalence principle is violated eiter way. Moreover, the box can be removed just before infall, after an appropriate state is prepared, since the properties of the zone cannot change substantially on the timescale . In order to keep the discussion general, I will not appeal to a CFT dual Mal97 , nor to any other assumptions about the fundamental nature of the microscopic degrees of freedom.
4.3.2 The Minable Zone is a Subsystem
An important question is what constitutes the black hole, i.e., what physical degrees of freedom correspond to its Hilbert space. For an ordinary thermodynamic system, one only considers microstates consistent with the macroscopic (“coarsegraining”) conditions imposed (for example, excitations confined to a cavity of some radius). For the black hole, I take these conditions to be those assumed in the derivation of the laws of black hole mechanics: the metric is a vacuum Schwarzschild (or Kerr) solution with energy as measured by a distant observer.
The energy is, in a sense, purely a feature of the geometry; the stress tensor vanishes everywhere. Yet, black holes share a key property with other thermodynamic systems: the energy can be lowered by mining, consistent with the First Law. Hence, the minable modes in the zone, , must be considered a subsystem of the black hole.
On the other hand, the black hole interior, , cannot be directly accessed by an external observer. But these are the only observers to whom the horizon entropy, temperature, and the mass of the black hole have operational meaning. Hence it does not seem natural to include interior field theory modes in .
However, I will be considering ideas in which the interior is identified with distant degrees of freedom accessible to an exterior observer. My goal is to argue against these proposals, so it is important that they are not trivially excluded from the start. In any case, it is not obvious that alone constitutes the black hole’s degrees of freedom. Therefore I will allow to contain a “hidden” factor , some or all of which may be associated with the interior.
Without loss of generality, the black hole Hilbert space in which the thermal density matrix acts can thus be written as
(30) 
4.3.3 The Canonical Zone Entropy is Additive
Consider first the canonical ensemble. In a field theory calculation without a cutoff, the thermal entropy of the zone, , would diverge due to ultraviolet modes near the horizon. But black hole thermodynamics dictates that the total thermal entropy is . This is consistent with a Planck scale cutoff in the field theory. However, there are a number of possibilities for how the zone contributes to the total entropy .
The simplest possibility, which I will not assume, is that the Planck cutoff, when properly derived from the underlying theory, is such that the zone is entirely responsible for the BekensteinHawking entropy: . Then all states in the microcanonical ensemble would trivially be pure states of the zone (and so have a firewall). This may be the case: in standard gravity, effective field theory should be a good approximation up to the Planck scale, so the canonical entropy of the zone alone satisfies .
However, suppose we adopt a conservative definition of “semiclassical”, a relatively low enough frequency cutoff, e.g. in Planck units. Then the semiclassically minable zone would represent only a subsystem of the black hole. Hence, the black hole may contain additional degrees of freedom , which are hidden from the outside observer or protected from semiclassical access. This is the most general possibility. Subadditivity of the entropy of subsystems implies that
(31) 
In fact, however, the canonical entropies of the zone and the hidden degrees of freedom must be additive:
(32) 
This follows from general properties of the canonical ensemble, and from the definition of as consisting of degrees of freedom that can be extracted from the black hole. Consider an ordinary system, such as a cavity filled with blackbody radiation, in a thermal state with finite entropy . Let “” and “” be the left and right half of the cavity. Defined strictly geometrically, the von Neumann entropy of “” diverges due to the entanglement entropy of ultraviolet modes near the dividing surface. However, an entangled mode cannot escape from the cavity even if a hole is opened or a wire inserted. If it did, then in equilibrium it would be replaced by energy from the heat bath. But the replacement would not have the same entanglement with “H”. As a result, the total entropy of the cavity would change, at fixed temperature. In this sense, entangled systems inside a thermal system cannot participate in the canonical ensemble. By contrast, if the division of the cavity is implemented by inserting a wall with appropriate boundary conditions, the entanglement will be eliminated. Then the entropy will satisfy , and all parts of “” can be exchanged with the heat bath.
But the latter case is the one analogous to the black hole, because was defined to consist of minable modes. If the inequality (31) was strict, then and would have mutual information. Then the exchange of with heat bath degrees of freedom would lead to a buildup of mutual information between the heat bath and the black hole, and to an increase in the canonical entropy of the black hole. This is impossible.
In the black hole case, it is important that and are allowed to interact, because only can be semiclassically coupled to a heat bath. If they could not interact, then the information in could not get out in the evaporation process. This interaction presents no obstruction, however, because they can only interact at the stretched horizon. That is, information from must enter through modes that get stretched below the cutoff, and viceversa. Otherwise, would not be hidden, which would simplify my argument. As discussed in Sec. 2.3, the minable wavepackets can be taken to have support only away from the stretched horizon without affecting their crucial properties. They will still carry nearly as much energy as a Schwarzschild frequency eigenstate, and they will have entropy in the infalling vacuum.
In fact the difficulty introduced by this interaction is no greater than in any ordinary thermodynamic system. For example, instead of the divided cavity, consider now a cavity with a ball “” in the center. The ball is coupled to the heat bath only through the radiation “”, which has only short range interactions with “”, much shorter than the distance between the ball and the outer wall of the cavity. The canonical ensemble still factorizes if we slightly redefine “” to exclude the interaction region.
4.3.4 The Microcanonical Ensemble Factorizes
Additivity of the canonical entropy implies that and can be treated as independent systems coupled to the same heatbath. Therefore, even if there exist hidden degrees of freedom , one can go over to the microcanonical ensembles for and independently. The microcanonical ensemble for spans a Hilbert space of finite dimension , where is the canonical entropy of . If , then there also exists a microcanonical Hilbert space for the hidden degrees of freedom, , with dimension , where . The full microcanonical ensemble for the black hole is . Like any outer product, it admits a basis consisting entirely of product states:
(33) 
In each basis element, the state of the zone is pure. Thus, if an interior exists, the zone and interior together are in a product state
(34) 
i.e., completely unentangled. This is true whether the interior is modelled as independent degrees of freedom, or identified with degrees of freedom in or in the distant Hawking radiation, by any map, unitary or not.
Of course, it is not important that the state of be exactly pure. For a firewall, it suffices that its entropy is much smaller than its canonical entropy, in each basis element. As discussed above, the division into subsystems and could be somewhat blurred by boundary effects. This is true for any thermodynamic system, as in the example of the radiationfilled cavity with a ball “” in the center. But if both subsystems are large and interactions are localized to their shared boundary, then independently of the detailed definition of , one can find a complete basis of the microcanonical ensemble of such that in every state, the entropy of is much smaller than it would be in the canonical ensemble.
One can easily estimate the probability of seeing no particles in a general product state. For each mode, the infalling vacuum is the entangled pure state
(35) 
In each basis element identified above, the states of and form a product state, which may be mixed or pure. Its overlap with the vacuum is maximized if this product state is , when the probability of observing the vacuum is . Hence the probability of observing a particle is at least , mode by mode, or about for modes with thermal wavelength. The minable zone contains of order independent modes (with a Planck scale cutoff). This is a firewall; the probability of seeing no particles at all (the infalling vacuum) is .^{14}^{14}14Of course, the product state obstruction also applies in the more restrictive setting of a linear unitary stateindependent map. In this case, I have already exhibited a different obstruction (Sec. 3) which applies to arbitrary states.
4.4 A Complete Basis of Firewall States Violates the Equivalence Principle
Product states span the whole Hilbert space, but they do not constitute it, since the product form is not preserved by linear combinations. This appears to leave a loophole: for a large system, product states are extremely rare with respect to the Haar measure Pag93 . Generic (Haarrandom) pure states are highly entangled. In such states, the state of will be a thermal density matrix, identical to the state one would obtain from the infalling vacuum. This is precisely the setting where a donkey map can restore the infalling vacuum even though is purified into a (naively) different state by a (naively) different system.^{15}^{15}15In a separate publication Bou13b , I argue that for generic states, the donkey map is overkill: the infalling state cannot deviate from the vacuum even in situations where the equivalence principle demands that it must. But the mere existence of a complete basis of firewall states, which has been demonstrated in the previous subsection, is incompatible with the properties expected of deviations from the vacuum in curved spacetime regions.
Consider a freely falling detector in a vacuum spacetime region with curvature radius . The adiabatic theorem dictates BirDav that the probability for detecting particles of characteristic frequency is suppressed exponentially, like . This is satisfied by black holes in the infalling vacuum: the zone is at a temperature , so Boltzmann suppression of energetic quanta yields a result consistent with the adiabatic theory. In particular, the atypical states where the black hole emits a highenergy object are not Haarsuppressed. Unlike product states, they do constitute a subspace; and this subspace has dimension exponentially smaller than . These are the atypical states consistent with the adiabatic vacuum. By contrast, all product states are firewall states, but they do not constitute a Hilbert space. Yet, they span the entire Hilbert space and so are not Boltzmann suppressed.
Moreover, particle detection in the adiabatic vacuum in curved space is not sharply localized. A soft particle of energy might be encountered anywhere in a spacetime region with curvature radius . A freely falling observer may also find more energetic excitations but they must be exponentially suppressed. Such particles are indeed predicted with the appropriate Boltzmann suppression in the Hawking temperature, and again they can occur anywhere in the zone. By contrast, the firewall in the product state basis is sharply localized to the apparent horizon of the black hole. The location is the same for all firewall states. There is no comparably sharp effect anywhere else, for any other distinct choice of Haarrare states. At the level of the theory, this violates the equivalence principle: the horizon is a special place. Then it is not clear what is gained by arguing that entangled states are smooth.
Acknowledgements.
I would like to thank the organizers of the CERN workshop on Black Hole Horizons and Quantum Information, March 2013, where the main results of this paper were first presented. I have benefitted from valuable discussions with many colleagues, especially S. Giddings, D. Harlow, D. Mainemer Katz, D. Marolf, J. Polchinski, V. Rosenhaus, D. Stanford, and L. Susskind. This work was supported by the Berkeley Center for Theoretical Physics, by the National Science Foundation (award numbers 1002399, 0855653 and 0756174), by fqxi grant RFP31004, by “New Frontiers in Astronomy and Cosmology”, and by the U.S. Department of Energy under Contract DEAC0205CH11231.References
 (1) S. W. Hawking, “Breakdown of Predictability in Gravitational Collapse,” Phys. Rev. D 14 (1976) 2460–2473.
 (2) J. D. Bekenstein, “Black holes and the second law,” Nuovo Cim. Lett. 4 (1972) 737–740.
 (3) J. D. Bekenstein, “A Universal Upper Bound on the Entropy to Energy Ratio for Bounded Systems,” Phys. Rev. D 23 (1981) 287.
 (4) H. Casini, “Relative entropy and the Bekenstein bound,” Class.Quant.Grav. 25 (2008) 205021, arXiv:0804.2182 [hepth].
 (5) G. ’t Hooft, “Dimensional reduction in quantum gravity,” grqc/9310026.
 (6) L. Susskind, “The World as a hologram,” J. Math. Phys. 36 (1995) 6377–6396, hepth/9409089.
 (7) R. Bousso, “A covariant entropy conjecture,” JHEP 07 (1999) 004, hepth/9905177.
 (8) E. E. Flanagan, D. Marolf, and R. M. Wald, “Proof of Classical Versions of the Bousso Entropy Bound and of the Generalized Second Law,” Phys. Rev. D 62 (2000) 084035, hepth/9908070.
 (9) J. Maldacena, “The Large limit of superconformal field theories and supergravity,” Adv. Theor. Math. Phys. 2 (1998) 231, hepth/9711200.
 (10) J. Preskill, “Do black holes destroy information?,” hepth/9209058.
 (11) L. Susskind, L. Thorlacius, and J. Uglum, “The Stretched horizon and black hole complementarity,” Phys. Rev. D 48 (1993) 3743, hepth/9306069.
 (12) C. R. Stephens, G. ’t Hooft, and B. F. Whiting, “Black hole evaporation without information loss,” Class. Quant. Grav. 11 (1994) 621–648, grqc/9310006.
 (13) A. Almheiri, D. Marolf, J. Polchinski, and J. Sully, “Black Holes: Complementarity or Firewalls?,” arXiv:1207.3123 [hepth].
 (14) A. Almheiri, D. Marolf, J. Polchinski, D. Stanford, and J. Sully, “An Apologia for Firewalls,” arXiv:1304.6483 [hepth].
 (15) R. D. Sorkin, “The statistical mechanics of black hole thermodynamics,” arXiv:grqc/9705006 [grqc].
 (16) S. L. Braunstein, “Black hole entropy as entropy of entanglement, or it’s curtains for the equivalence principle,” arXiv:0907.1190v1 [quantph].
 (17) S. D. Mathur, “The Information paradox: A Pedagogical introduction,” Class.Quant.Grav. 26 (2009) 224001, arXiv:0909.1038 [hepth].
 (18) S. B. Giddings, “Models for unitary black hole disintegration,” Phys.Rev. D85 (2012) 044038, arXiv:1108.2015 [hepth].
 (19) S. B. Giddings, “Black holes, quantum information, and unitary evolution,” Phys.Rev. D85 (2012) 124063, arXiv:1201.1037 [hepth].
 (20) S. B. Giddings and Y. Shi, “Quantum information transfer and models for black hole mechanics,” arXiv:1205.4732 [hepth].
 (21) L. Susskind, “Black Hole Complementarity and the HarlowHayden Conjecture,” arXiv:1301.4505 [hepth].
 (22) E. Verlinde and H. Verlinde, “Black Hole Entanglement and Quantum Error Correction,” arXiv:1211.6913 [hepth].
 (23) K. Papadodimas and S. Raju, “An Infalling Observer in AdS/CFT,” arXiv:1211.6767 [hepth].
 (24) Y. Nomura, J. Varela, and S. J. Weinberg, “Low Energy Description of Quantum Gravity and Complementarity,” arXiv:1304.0448 [hepth].
 (25) E. Verlinde and H. Verlinde, “Passing through the Firewall,” arXiv:1306.0515 [hepth].
 (26) E. Verlinde and H. Verlinde, “Black Hole Information as Topological Qubits,” arXiv:1306.0516 [hepth].
 (27) J. Maldacena and L. Susskind, “Cool horizons for entangled black holes,” arXiv:1306.0533 [hepth].
 (28) R. Bousso, “Quantum Mechanics vs. the Equivalence Principle.,”. Talk given at the Workshop on Black Hole Horizons and Quantum Information, March 2013: http://cds.cern.ch/record/1532382.
 (29) D. Marolf and J. Polchinski, “Gauge/Gravity Duality and the Black Hole Interior,” arXiv:1307.4706 [hepth].
 (30) B. D. Chowdhury, “Cool horizons lead to information loss,” arXiv:1307.5915 [hepth].
 (31) W. Wootters and W. Zurek, “A single quantum cannot be cloned,” Nature 299 (1982) 802–803.
 (32) L. Susskind and L. Thorlacius, “Gedanken experiments involving black holes,” Phys. Rev. D49 (1994) 966–974, arXiv:hepth/9308100.
 (33) P. Hayden and J. Preskill, “Black holes as mirrors: quantum information in random subsystems,” JHEP 09 (2007) 120, arXiv:0708.4025 [hepth].
 (34) D. Harlow and P. Hayden, “Quantum Computation vs. Firewalls,” JHEP 1306 (2013) 085, arXiv:1301.4504 [hepth].
 (35) W. G. Unruh, “Notes on black hole evaporation,” Phys. Rev. D 14 (1976) 870.
 (36) R. Bousso, B. Freivogel, S. Leichenauer, and V. Rosenhaus, “Eternal inflation predicts that time will end,” Phys. Rev. D83 (2011) 023525, arXiv:1009.4698 [hepth].
 (37) E. Lieb and M. Ruskai, “Proof of the strong subadditivity of quantummechanical entropy,” J.Math.Phys. 14 (1973) 1938–1941.
 (38) W. G. Unruh and R. M. Wald, “Acceleration Radiation and Generalized Second Law of Thermodynamics,” Phys. Rev. D 25 (1982) 942–958.
 (39) W. G. Unruh and R. M. Wald, “What happens when an accelerating observer detects a Rindler particle,” Phys.Rev. D29 (1984) 1047–1056.
 (40) A. R. Brown, “Tensile Strength and the Mining of Black Holes,” arXiv:1207.3342 [grqc].
 (41) R. Bousso, “Complementarity Is Not Enough,” arXiv:1207.5192 [hepth].
 (42) S. G. Avery, B. D. Chowdhury, and A. Puhm, “Unitarity and fuzzball complementarity: ’Alice fuzzes but may not even know it!’,” arXiv:1210.6996 [hepth].
 (43) B. Freivogel and L. Susskind, “A framework for the landscape,” hepth/0408133.
 (44) R. Bousso and L. Susskind, “The Multiverse Interpretation of Quantum Mechanics,” arXiv:1105.3796 [hepth].
 (45) L. Susskind, “The Transfer of Entanglement: The Case for Firewalls,” arXiv:1210.2098 [hepth].
 (46) R. Bousso, “Observer Complementarity Upholds the Equivalence Principle,” arXiv:1207.5192v1 [hepth].
 (47) H. Verlinde. Seminar at the Simons Symposium on Quantum Entanglement, Caneel Bay, February 2013.
 (48) D. N. Page, “Expected entropy of a subsystem,” Phys. Rev. Lett. 71 (1993) 1291–1294, grqc/9305007.
 (49) R. Bousso, “Frozen Vacuum,” arXiv:1308.3697 [hepth].
 (50) J. M. Bardeen, B. Carter, and S. W. Hawking, “The Four Laws of Black Hole Mechanics,” Commun. Math. Phys. 31 (1973) 161.
 (51) S. W. Hawking, “Particle Creation By Black Holes,” Commun. Math. Phys. 43 (1975) 199.
 (52) S. W. Hawking, “Black Holes and Thermodynamics,” Phys. Rev. D 13 (1976) 191–197.
 (53) S. Hawking and D. N. Page, “Thermodynamics of Black Holes in antiDe Sitter Space,” Commun.Math.Phys. 87 (1983) 577.
 (54) N. D. Birrell and P. C. W. Davies, Quantum fields in curved space. Cambridge University Press, Cambridge, England, 1982.