Amazon introduced Throw Away the Key Encryption (TAKE) for its Ring cameras intending to limit access to video footage by the company and law enforcement. While it restricts access to stored video keys for 24 hours, it still requires cloud decryption for Ring’s features, raising significant privacy concerns.
- TAKE temporarily stores encryption keys in Ring’s cloud for feature processing.
- The approach is an incremental privacy improvement, not full end-to-end encryption.
- Law enforcement access remains possible under current company practices.
What happened
Amazon recently deployed a feature called Throw Away the Key Encryption (TAKE) for its Ring security cameras. TAKE changes how encryption keys are managed by allowing users’ devices to hold keys primarily, but also temporarily sharing those keys with Ring’s cloud for up to 24 hours. This temporary access allows Ring to provide value-added features like video descriptions, smart alerts, and video search — functions not possible with strict end-to-end encryption.
This method marks a shift from the previous process, where Ring continuously held the decryption keys, enabling uninterrupted access to footage stored on their servers. Under TAKE, the keys are deleted after 24 hours, though they can be re-sent from a user’s device when old video is accessed or smart features are utilized. Despite these efforts, Ring still maintains critical access to unencrypted footage during the period it holds the keys, keeping the door open for government or law enforcement access if compelled.
Why it matters
TAKE is an improvement over Ring’s default full cloud access encryption model, as it limits how long Ring holds the keys and footage in unencrypted form. However, it falls short of delivering real privacy protections that users demand in personal security cameras. Because key access is temporary and features reliant on cloud processing still require decrypting footage remotely, Ring effectively replicates the vulnerabilities inherent in standard encryption-at-rest models where the service provider controls keys.
Furthermore, features like video descriptions and searchable video content, while valuable to users, expose metadata and insights about video content to Ring. This metadata could be leveraged for surveillance or shared with authorities without the same user protections that true end-to-end encryption would provide. Account recovery keys stored on cameras and existing indexing of footage content add additional risks to user privacy, enabling mass surveillance possibilities.
What to watch next
Critics and privacy advocates will be closely monitoring how Ring evolves TAKE’s protections, particularly around minimizing metadata exposure and strengthening assurances that keys will not be accessible to employees or law enforcement. Amazon’s public commitments about not retaining backups of keys or decrypted video and deleting content from servers will face scrutiny in light of the ongoing need for cloud processing.
Regulators and lawmakers may also push for stronger encryption standards in consumer security devices like Ring cameras given the persistent privacy gaps. The balance between smart home convenience features and user privacy protections remains a crucial battleground. Eventually, adoption of genuine end-to-end encryption models that do not expose plaintext video to providers, while maintaining desired features, will be needed to satisfy privacy expectations at scale.