Home Tech Ring says its new encryption limits what it can give police
Tech

Ring says its new encryption limits what it can give police

Share
Ring says its new encryption limits what it can give police
Share

Ring has a new way to protect your videos. It’s developed an encryption method called TAKE, short for Throw Away the Key Encryption, that the Amazon-owned company says will protect your videos without traditional end-to-end encryption. TAKE limits when and why Amazon’s cloud can access those videos, while still providing features like smart alerts for people and packages, AI-powered video search, and video descriptions.

The feature is rolling out gradually starting in September, regardless of whether you have a subscription, and will become the default encryption for all Ring customers.

Image: Ring

TAKE arrives during a year of intense scrutiny for Ring, driven by its ties to law enforcement and the privacy implications of its AI-powered Search Party feature. Ring says TAKE changes what the company can hand over to law enforcement. “Ring will only be able to provide non-video information … and encrypted video files in response,” Ring spokesperson Sam McGee said in an email to The Verge. However, it doesn’t completely eliminate the privacy trade-off of cloud-based cameras.

Ring says TAKE uses unique, rotating encryption keys for your footage, stored in a secure enclave and accessible only under strict conditions — based on the features you enable on your account. Currently, footage captured by Ring cameras is encrypted in transit to the cloud and at rest, and then decrypted for Ring to process for those smart features. With TAKE, the encryption keys change for every five minutes of footage. Ring stores copies of those keys to decrypt the footage, but throws away each copy within 24 hours, “leaving you with the keys and full control of your videos,” according to Ring.

TAKE was developed using Messaging Layer Security, an open standard from the Internet Engineering Task Force, according to Ring. The company says it is “inspired by the privacy principles of E2EE (end-to-end encryption),” which Ring offers on some of its cameras. However, the two systems work differently. With E2EE, Ring never has the keys and can’t process your video for cloud-based features. Both options are available on newer cameras that encrypt on-device, and you can switch between the two. Older cameras encrypt at cloud ingress and only support TAKE.

A screenshot from the TAKE white paper published by Ring.

A screenshot from the TAKE white paper published by Ring.

According to a white paper the company published today, Ring’s copy of those keys is managed inside an AWS Nitro Enclave, to which Ring’s access is restricted by “access controls, cryptography, and hardware isolation.” The company claims there is no persistent storage and no way for a Ring employee to access it. The stored keys can only be unlocked by the enclave through cryptographic attestation that proves it’s running the exact software image Ring approved. The enclave releases a temporary key when an enabled service requests it.

Each key is permanently deleted after 24 hours — a window McGee told The Verge allows for processing its current cloud-based features — and no backups are kept. To view older footage, an authorized device running the Ring app (such as your phone or computer) must send the keys back to Ring for that session. Ring claims key delivery is push only, meaning Amazon’s servers can’t force devices to hand over your keys remotely; only you can request one.

If you lose access to your device, Ring says there are several recovery methods, all of which are only accessible to the customer. These include cloud backup via your phone, a passphrase, passkey, another authorized device, and camera-based recovery. If all those fail, you won’t be able to access encrypted content.

The white paper details how the keys are generated and how Ring continuously “throws away” your old keys. Ring says it’s continuing to harden this architecture:

Deletion is continuous rather than a single event at the 24-hour mark. Content encryption keys rotate every five minutes, and as each key ages past 24 hours, CMMS [Cloud Member Management Service] ratchets forward the corresponding intermediary secret in the key derivation hierarchy. Ratcheting applies a one-way key derivation function to overwrite a managed secret with its derived output and discards the original, making it cryptographically infeasible to reconstruct. […] The CMMS database is configured with no backups. This deletion is designed to be irreversible.

TAKE isn’t E2EE, but it limits Ring’s access

Ring says that “only you retain the keys to your video” with TAKE. But TAKE isn’t E2EE. Ring has access for up to 24 hours and can receive keys again when you pull up older videos. You can also share the keys with others. With E2EE enabled on Ring cameras, none of that is possible, making it the stronger privacy option.

Ring’s main reason for developing TAKE is to preserve cloud-based features you lose with E2EE. But as the footage goes to Amazon’s servers for processing, it still has the privacy trade-off of cloud-based cameras. Cloud processing can deliver more sophisticated features, but basic on-device intelligence can still alert you to people and packages.

“Where TAKE is enabled, Ring will only be able to provide non-video information (such as basic subscriber information) and encrypted video files in response to the valid legal process.”

— Sam McgEe

Competitors including Reolink and Eufy offer cameras and hubs that can store and process footage locally, so it doesn’t need to be done in the cloud. Ring also has local processing through Ring Edge on its Ring Alarm Pro hub, but that doesn’t work with E2EE.

Ring says many of its features can’t run locally. “Features that require cloud processing include Unusual Event Alert, Video Descriptions, Smart Alerts, and Video Search, for example,” McGee said. “These features rely on models and infrastructure that cannot run locally on camera hardware.”

The Verge also asked McGee about concerns users might have regarding how TAKE processes videos in relation to privacy and law enforcement access:

What happens if Ring is subpoenaed by law enforcement? Does TAKE prevent law enforcement and others from accessing footage?

“Where TAKE is enabled, Ring will only be able to provide non-video information (such as basic subscriber information) and encrypted video files in response to the valid legal process. We have updated our Law Enforcement Guidelines to reflect this change.”

Does this change Ring’s Community Requests program and the partnership with Axon?

“Community Requests remains a transparent way for local public safety agencies to request footage from customers to support an official investigation. Customers always choose whether to respond to a Community Request and what they share. If they choose to ignore a request, the Requesting Agency is never notified. TAKE does not change this.”

Do governments have a backdoor into TAKE?

“No. Building a backdoor would undermine the enhanced security and privacy that we designed TAKE to deliver.”

Does Ring train on any data or metadata from users’ Ring devices?

“Ring only trains on video recordings that have been made publicly available, or on recordings from users who have given Ring explicit permission to use them for this purpose. Users can revoke permission at any time.”

When asked if TAKE had been independently evaluated, McGee said, “TAKE is built on Messaging Layer Security, an open standard developed and reviewed through the IETF. We are publishing a detailed technical whitepaper explaining how the system works.”

You can read the current white paper to see how Ring describes TAKE’s protections.

Ring’s TAKE appears to address many of the concerns around cloud processing, allowing a balance between security, privacy, and convenience, especially compared to E2EE, which gives you privacy but not the Ring features you probably bought these cameras for. While TAKE is built on a standard, Ring developed the parts that involve throwing away the key itself, meaning you still have to trust Amazon and Ring.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.


Source link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep in touch

Subscribe to our newsletter to get our newest articles instantly!

    Copyright 2025. All rights reserved