The short version
- Ring’s new TAKE encryption method rotates keys every five minutes and permanently deletes them from Amazon’s servers after one day.
- The system allows the company to process video for smart alerts and search features, distinguishing it from traditional end-to-end encryption which blocks such processing.
- Rollout begins in September as a default setting for all customers, addressing ongoing scrutiny regarding law enforcement access and data privacy.
Ring, the Amazon-owned home security camera brand, is implementing a new encryption architecture designed to limit the company’s ability to access user video footage while preserving its suite of cloud-based smart features. Dubbed TAKE, or Throw Away the Key Encryption, the system represents a middle ground between standard cloud storage and strict end-to-end encryption. The feature will begin rolling out gradually in September and is set to become the default protection method for all Ring customers, regardless of their subscription status.
The core mechanism of TAKE involves generating unique encryption keys for every five minutes of recorded footage. These keys are stored temporarily within a secure AWS Nitro Enclave, a hardware-isolated environment that restricts access through cryptographic attestation and strict access controls. According to Ring’s technical documentation, the company retains copies of these keys only long enough to process video for features such as person detection, package alerts, and AI-powered search. Once a key reaches 24 hours of age, it is permanently deleted from Ring’s servers using a ratcheting process that makes reconstruction cryptographically infeasible.
This approach differs significantly from end-to-end encryption (E2EE), which Ring also offers on newer devices. Under E2EE, the company never possesses the decryption keys, meaning it cannot analyze video content for smart features or provide descriptions of events. TAKE allows Ring to maintain its value-added services by accessing footage within that 24-hour window, after which the company loses the ability to decrypt the data without user intervention. Users who wish to view older footage must send their own stored keys from an authorized device back to Ring for that specific session.
The introduction of TAKE arrives amid heightened scrutiny of Ring’s relationship with law enforcement and the privacy implications of its AI capabilities, including the controversial Search Party feature. A company spokesperson stated that under the new system, Ring will only be able to provide non-video information or encrypted video files in response to legal requests. Because the keys are destroyed after a day, the company claims it cannot decrypt older footage even if compelled by authorities, provided the user has not retained access to their own keys.
Ring emphasizes that key delivery is push-only, meaning Amazon’s servers cannot remotely force devices to surrender decryption keys. Access remains under the control of the account holder, who can manage keys through various recovery methods including cloud backups on personal phones, passphrases, or other authorized devices. If a user loses access to all recovery options, the encrypted content becomes permanently inaccessible, underscoring the trade-off between security and convenience.
The technical implementation relies on Messaging Layer Security, an open standard developed by the Internet Engineering Task Force. Ring describes the system as inspired by E2EE privacy principles but engineered to support cloud processing. Older cameras that encrypt data at cloud ingress will support only TAKE, while newer models with on-device encryption capabilities allow users to switch between TAKE and full E2EE depending on their preference for feature functionality versus maximum privacy.
Critics of cloud-based surveillance have long argued that any system allowing the provider to access video content poses inherent privacy risks. While TAKE reduces the window of vulnerability by limiting key retention to 24 hours, it does not eliminate the possibility of access during that period. The company asserts that no persistent storage or employee access exists within the Nitro Enclave, and that the deletion process is continuous and irreversible, designed to prevent any backdoor retrieval of historical data.
As the feature rolls out, users will need to adapt to a new paradigm where their video security depends partly on their own key management. The shift signals a broader industry trend toward balancing advanced AI analytics with growing consumer demand for data protection. By making TAKE the default, Ring is attempting to standardize a level of privacy that accommodates both its business model and the increasing regulatory and public pressure surrounding smart home surveillance.
Sources behind this briefing
Go to the original reporting
- The Verge↗Ring says its new encryption limits what it can give police