Ring is rolling out a new encryption system called TAKE, short for Throw Away the Key Encryption, that will become the default for all Ring camera users starting in September, regardless of subscription status. The Amazon-owned company says the system limits when its cloud can access video footage, while still enabling features like smart alerts for people and packages, AI-powered video search, and video descriptions. The announcement comes during a year of heightened scrutiny over Ring鈥檚 law enforcement ties and the privacy implications of its AI-driven Search Party feature. Ring says TAKE changes what it can hand over to police, with a spokesperson stating the company will only provide non-video information and encrypted video files in response to requests.
TAKE uses unique encryption keys that rotate every five minutes of footage, stored in a secure enclave. Ring keeps copies of those keys for up to 24 hours, then deletes them permanently with no backups, leaving the customer with full control. The keys can only be unlocked through cryptographic attestation proving the enclave is running Ring-approved software, and access is restricted by access controls, cryptography, and hardware isolation. The system is built on Messaging Layer Security, an open standard from the Internet Engineering Task Force, and Ring says it was inspired by end-to-end encryption principles. The company published a white paper detailing the architecture.
Unlike true end-to-end encryption, which Ring offers on some newer cameras and where the company never holds keys, TAKE gives Ring access for up to 24 hours and allows the cloud to receive keys again when a customer views older footage. Both options are available on newer cameras that encrypt on-device, and users can switch between them. Older cameras encrypt at cloud ingress and only support TAKE. Ring says TAKE preserves cloud-based features that E2EE would disable, including unusual event alerts, video descriptions, smart alerts, and video search, which the company says cannot run locally on camera hardware.
For older footage, an authorized device running the Ring app must send keys back to Ring for that session. Ring says key delivery is push only, so Amazon鈥檚 servers cannot force devices to hand over keys remotely. If a user loses access to their device, recovery methods include cloud backup via phone, a passphrase, a passkey, another authorized device, or camera-based recovery. If all those fail, the user cannot access encrypted content. Ring says deletion is designed to be irreversible, with keys ratcheting forward past the 24-hour mark using a one-way derivation function.
Ring addressed law enforcement and privacy concerns directly. Its Community Requests program, which lets local public safety agencies ask customers for footage, remains unchanged, and customers always choose whether to respond. Ring said it is not building a backdoor that would undermine TAKE鈥檚 security. Regarding training data, Ring says it only trains on publicly available recordings or those where users gave explicit permission, which can be revoked at any time. When asked about independent evaluation, Ring noted TAKE is built on an open standard developed through the IETF and pointed to its published white paper.
Competitors like Reolink and Eufy offer cameras that store and process footage locally, avoiding cloud processing entirely. Ring has local processing through its Ring Edge feature on the Ring Alarm Pro hub, but that does not work with E2EE. The company maintains that many of its more advanced features rely on cloud models that cannot run on camera hardware. TAKE does not eliminate the privacy trade-off inherent in cloud-based cameras, as footage still goes to Amazon鈥檚 servers for processing, though access is now more restricted than before.
More cybersecurity news from TechManNews.







