Ring TAKE encryption becomes default to balance privacy and cloud features
Amazon-owned Ring is implementing 'Throw Away the Key Encryption' (TAKE) as a default setting, utilizing the Messaging Layer Security standard to rotate encryption keys every five minutes. While the system enhances privacy by deleting temporary keys after 24 hours, Ring retains the ability to access keys for cloud-based features like Smart Alerts and must still comply with valid legal requests for encrypted video.
Key Takeaways
- Encryption keys rotate every five minutes on-device for new models or in the cloud for older hardware
- Amazon-owned Ring deletes its temporary key copies after 24 hours, leaving long-term access only to device owners
- Cloud-based features like Smart Alerts remain functional under TAKE, unlike full end-to-end encryption which disables them
- Ring will still provide encrypted video files and subscriber data to law enforcement in response to valid legal requests
Why It Matters
This shift to Ring TAKE encryption represents a strategic attempt to mitigate years of privacy controversies, including a $5.8 million FTC settlement over unauthorized video access. By automating key deletion after 24 hours, Ring limits its own long-term data liability while preserving the high-margin AI features that differentiate its hardware. For the broader smart home ecosystem, this move signals a transition toward 'privacy-by-default' architectures that attempt to satisfy both regulatory scrutiny and consumer demand for intelligent cloud processing. Watch for whether this technical compromise reduces the volume of successful law enforcement data requests or if the provision of encrypted files remains a point of contention for privacy advocates.
Additional Context
Ring's parent company Amazon has faced sustained regulatory pressure over its smart home data practices, which contextualizes the urgency behind the TAKE rollout. In June 2023, the FTC finalized a $5.8 million settlement requiring Ring to delete videos and images collected without consent, and in May 2024, Ring disclosed it had provided footage to police without user consent in 11 emergency cases, prompting renewed calls from senators for a federal privacy law covering smart home devices. The TAKE encryption default appears designed to reduce the surface area for such controversies by ensuring keys are destroyed on a fixed schedule, limiting the window during which Ring could technically comply with data requests.
Competing smart home camera makers have taken different approaches to the privacy-versus-functionality tradeoff. Apple's HomeKit Secure Video, which processes footage on-device before encrypting and storing it in iCloud, was expanded in iOS 17 to support up to 10 cameras without counting against iCloud storage, positioning Apple as the privacy-first alternative for security-conscious consumers. Meanwhile, Axon Bodycam's cloud platform, which serves law enforcement agencies, uses AES-256 encryption with role-based access controls but retains footage indefinitely per agency retention policies, illustrating the spectrum of key-management philosophies across the video surveillance market. Ring's TAKE approach sits between these poles: more aggressive key rotation than traditional cloud storage, but less restrictive than fully on-device processing.
The Messaging Layer Security standard that underpins TAKE has gained traction beyond Ring's implementation. MLS was ratified as RFC 9420 by the IETF in April 2023 and has since been adopted by Meta for WhatsApp's group chat encryption and by Cisco for Webex end-to-end encryption. Cisco announced in March 2025 that Webex meetings would use MLS-based encryption for all enterprise sessions, citing the protocol's ability to handle large group key rotation efficiently. Ring's use of MLS for camera key rotation represents one of the first applications of the standard outside messaging and collaboration tools, extending its relevance into IoT and physical security contexts. The protocol's forward-secrecy guarantees mean that even if a key is compromised at one point, past and future sessions remain protected, a property that aligns with Ring's stated goal of minimizing exposure windows.
Read full article at ghacks.net
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source