Ring TAKE encryption standard becomes default to balance privacy and AI
Amazon's Ring is introducing a new encryption standard called TAKE (Throw Away the Key Encryption) as the default for its cloud-based video features. The standard, based on the IETF's Messaging Layer Security, allows for temporary server-side processing for features like object detection while maintaining user privacy by deleting encryption keys within 24 hours.
Key Takeaways
- TAKE protocol utilizes the IETF Messaging Layer Security standard to enable temporary server-side video processing.
- Encryption keys are stored in the cloud for a maximum of 24 hours before being permanently deleted.
- Cloud-based features like Smart Alerts for people, vehicles, and packages remain functional under the new default.
- Users retain the option to manually opt-in to full end-to-end encryption if they prefer to disable cloud processing.
Why It Matters
The shift to the TAKE standard represents a strategic attempt to solve the friction between high-level privacy and advanced computer vision features. By moving away from permanent end-to-end encryption as the default, Ring can maintain the utility of its Smart Alerts and object detection without permanently storing unencrypted user data. This move signals a broader industry trend where hardware manufacturers must engineer complex key-management systems to satisfy both regulatory scrutiny and consumer demand for AI-driven insights. Watch for whether this 'temporary key' model becomes a blueprint for other smart home and streaming security providers facing similar privacy litigation.
Additional Context
Ring's parent company Amazon has been under sustained regulatory pressure over its smart home data practices. In June 2024, the FTC filed a complaint against Amazon alleging that Ring's Alexa division recorded and stored children's voices without parental consent, and in January 2024 the company agreed to pay $25 million to settle those claims. That enforcement action created a direct incentive for Ring to build cryptographic architectures that limit data retention, which is precisely what the Ring TAKE encryption standard accomplishes by deleting keys within 24 hours. The IETF's Messaging Layer Security protocol, on which TAKE is built, was ratified as RFC 9420 in April 2023 and has since been adopted by WhatsApp, Cisco Webex, and Google Messages as a foundation for group messaging encryption. Ring's application of MLS to video key management represents one of the first known uses of the standard outside pure messaging contexts.
The broader smart home security market is converging on similar privacy-preserving architectures. Apple introduced Advanced Data Protection for iCloud in December 2022, extending end-to-end encryption to 23 data categories including HomeKit secure video, forcing competitors to match or differentiate. Google's Nest line relies on on-device processing for its AI features through the Nest Secure framework, which keeps video analysis local rather than sending footage to cloud servers. Ring's TAKE approach occupies a middle ground: it permits cloud processing for richer AI features while imposing strict key-deletion timelines. This positions Amazon to argue that its privacy posture is functionally equivalent to on-device processing, a claim that will likely face scrutiny from state attorneys general and the FTC as enforcement of IoT privacy norms intensifies.
From a technical standpoint, the MLS-based key rotation model that Ring employs has been benchmarked independently by academic researchers. A 2024 paper from the University of Birmingham's security group evaluated MLS performance at scale and found that group key updates could complete in under 50 milliseconds for groups of up to 50,000 members, suggesting that Ring's implementation should introduce negligible latency for single-device video sessions. The protocol's continuous key rotation also means that even if a server is compromised, the attacker gains access only to a narrow time window of footage. For the streaming and video infrastructure industry, Ring's deployment offers a reference architecture for any service that needs to run cloud-based computer vision on user-generated video while maintaining a defensible privacy posture against regulatory challenge.
Read full article at techcrunch.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source