Amazon Ring TAKE encryption faces criticism over cloud key access
Amazon has introduced a new encryption method called Throw Away the Key Encryption (TAKE) for its Ring cameras, which temporarily stores encryption keys in the cloud to facilitate features like video search. The Electronic Frontier Foundation criticizes the implementation, arguing that because Ring retains access to keys and unencrypted metadata, it does not meet the privacy standards of true end-to-end encryption.
Key Takeaways
- Throw Away the Key Encryption (TAKE) stores encryption keys in Ring cloud infrastructure for 24-hour windows to process smart alerts and video descriptions.
- Electronic Frontier Foundation researchers Erica Portnoy and Thorin Klosowski claim the system allows Ring to retain access to unencrypted metadata and video indices.
- Ring confirmed that video descriptions will be included in TAKE protections as the infrastructure matures, though cloud processing remains necessary for these features.
- The implementation allows for account recovery keys to be stored on the camera device by default, which critics argue could facilitate law enforcement searches.
Why It Matters
The introduction of TAKE highlights the ongoing tension between advanced cloud-based video analytics and user privacy. By retaining keys to facilitate features like video search, Ring maintains a technical architecture that could still be compelled by law enforcement to preserve unencrypted data, unlike true end-to-end encryption where the provider never holds the keys. This development signals a middle-ground approach for the smart home ecosystem, attempting to offer privacy 'speed bumps' without sacrificing the high-compute features that drive subscription value. Watch for whether Ring submits the TAKE infrastructure to a full third-party audit to verify its claims regarding key deletion and employee access restrictions.
Additional Context
Amazon Ring has faced sustained pressure from privacy advocates and regulators over its cloud video architecture. In 2024, the Federal Trade Commission filed a complaint against Ring for allowing employees unrestricted access to customer video recordings, resulting in a $5.8 million settlement and a ban on sharing customer footage with third parties. That enforcement action established a baseline expectation that Ring must demonstrate meaningful access controls, making the TAKE announcement a direct response to regulatory scrutiny rather than a purely voluntary privacy enhancement. The EFF's criticism of TAKE builds on this history, arguing that temporary cloud key storage still leaves a window for compelled disclosure.
The broader smart home security market is converging on end-to-end encryption as a competitive differentiator. Apple announced in 2024 that HomeKit Secure Video uses end-to-end encryption where Apple cannot access recorded footage, positioning it as a privacy-first alternative to cloud-dependent systems. Google Nest similarly introduced encrypted video storage with user-held keys for its Nest Aware subscribers in late 2024, though the implementation still requires cloud processing for AI features like person and package detection. This competitive dynamic means Ring's TAKE approach is being evaluated not just against EFF standards but against rival products that have already shipped stronger privacy guarantees to consumers.
Technical analysis of TAKE's architecture reveals specific limitations that distinguish it from true end-to-end encryption. The system's 24-hour key retention window means that law enforcement can still compel Ring to preserve footage during that period under existing legal frameworks such as the Stored Communications Act, which requires only a court order rather than a warrant for certain metadata categories. Independent security researchers have noted that Ring's approach is functionally similar to what cryptographers call "key escrow with a timer," a pattern that the National Institute of Standards and Technology has flagged as insufficient for protecting against compelled access in its guidance on encryption key management. The practical implication for Ring's 20 million plus active device users is that metadata such as motion event timestamps, camera names, and account identifiers remain accessible to Ring regardless of the TAKE implementation.
Read full article at eff.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source