Amazon Ring encryption privacy: TAKE still gives Ring 24-hour video access

Related

Share

Amazon has rolled out a new encryption system for its Ring cameras, and the pitch sounds like a privacy win: less footage sitting around for the company or police to access. But a closer look at how Amazon Ring encryption privacy actually works under this new setup suggests the upgrade is more modest than it appears, according to an analysis by the Electronic Frontier Foundation (EFF).

Key takeaways

  • Amazon’s new “Throw Away the Key Encryption” (TAKE) system stores video encryption keys in Ring’s cloud for 24 hours to power features like smart alerts and video search.
  • After that window, keys are deleted, but they get sent right back to Ring’s servers whenever a user wants to view older footage or use smart features.
  • EFF says TAKE is “barely different” from standard encryption-at-rest, where the company holds the keys the whole time.
  • Ring already offers true end-to-end encryption, where the company never holds the keys at all, but it’s optional rather than the default.
  • Law enforcement could still, in theory, compel Ring to retain keys or unencrypted footage, and features like video descriptions leave metadata exposed even when video content stays encrypted.

Amazon Launches Throw Away the Key Encryption for Ring Cameras

TAKE is Amazon‘s answer to growing pressure over how much surveillance footage tech companies keep sitting in the cloud, and it works by giving Ring temporary, time-limited access to encryption keys rather than permanent access. The goal, according to the company, is to cut down on the amount of video content available to Ring itself and, by extension, to law enforcement requesting that footage.

How TAKE Manages Encryption Keys and Deletion Timelines

Under the old system, Ring footage was encrypted in transit and at rest, but the company always held the decryption keys and always had access to the footage whenever it needed to run features like motion detection or smart alerts. TAKE changes that flow slightly. The user’s device holds a key, and Ring’s cloud infrastructure holds a copy temporarily so it can process features that the company says aren’t available under full end-to-end encryption, including video search, smart alerts, and AI-generated video descriptions.

That temporary access window lasts 24 hours, after which the key is deleted from Ring’s servers. But the moment a user wants to pull up an old clip or trigger a smart feature again, the key gets sent right back to the server. So the deletion isn’t really permanent — it’s a rolling cycle that resets every time the customer interacts with certain features.

Privacy Limitations of TAKE Compared to End-to-End Encryption

TAKE gives Ring a real but narrow improvement over the status quo, not the kind of airtight privacy protection that true end-to-end encryption offers. EFF’s assessment is blunt about this gap, noting that the new system “at least puts some restrictions on historical footage” but still leaves “serious holes worth exploring.”

Because features like smart alerts and video search require cloud processing, Ring has to decrypt footage stored on its own servers to deliver them. That means for up to 24 hours at a stretch, Ring has access to unencrypted video content — the exact kind of access that privacy-focused users are trying to avoid when they turn to encrypted camera systems in the first place. TAKE adds secure-enclave protections meant to make the base key material harder to export directly, but the keys are still released to services that can be modified, which limits how much protection those enclaves actually provide.

Why TAKE Still Resembles Standard Encryption-at-Rest

EFF’s central critique is that, in practice, TAKE ends up looking a lot like conventional encryption-at-rest, where the server holds the keys the whole time. The user’s device essentially functions like a hardware security module, making its key available to Ring’s servers whenever the company’s systems call for it. That’s an upgrade from constant access, but it’s a long way from a system where the company genuinely cannot reach the content.

Ring already offers a stronger alternative: true end-to-end encryption, where the service never holds the keys at any point and therefore can never access the footage, decrypted or otherwise. That option exists today, but it isn’t turned on by default. EFF argues that flipping the default to end-to-end encryption is the change that would actually deliver “the real sorts of privacy improvements we all want from video doorbells” — rather than a system that still routes decryption through company servers on a rolling basis.

Law Enforcement Access and Potential Surveillance Risks

Because TAKE still gives Ring temporary custody of both keys and unencrypted footage, the system leaves the door open to legal pressure that a fully end-to-end encrypted service wouldn’t face. This matters for anyone weighing whether smart-home cameras are a genuine step forward for digital privacy or just a modest patch on an old problem.

EFF points out that it remains technically possible for Ring to alter its current key-rotation practices if compelled by a legal order — for instance, being told to save content encryption keys or unencrypted video from memory to disk rather than deleting them after 24 hours. That’s the same structural risk that exists with any encryption-at-rest system where a company, rather than the user alone, controls the keys.

Ring told EFF that “By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content,” adding that it will “only preserve and provide encrypted video files in response to valid legal process” and that it has a policy of objecting to overbroad legal requests. EFF says it specifically asked Ring whether the company could be compelled to modify its practices to turn over or preserve unencrypted video — something that appears technically feasible — but the company did not directly address that scenario.

Metadata Like Video Descriptions Remain Exposed

Even when raw footage stays encrypted, the information Ring generates about that footage can still reach the company. Features like Smart Video Descriptions and Video Search require making descriptive text about clips available to the device owner, and Ring confirmed to EFF that “as Ring continues to expand and further strengthen TAKE’s protections, video descriptions will be included.” In other words, the video itself may stay locked, but a written summary of what’s in it doesn’t necessarily stay private.

EFF also flagged that account recovery keys are stored on the camera itself by default, and that indices of video content are currently available to the company. Combined, those two facts mean TAKE isn’t much of a shield against mass surveillance: law enforcement could, in theory, run a broad search across cameras for specific terms, then narrow in on cameras of interest, seize devices, decrypt account backups, and use that information to unlock specific encrypted videos.

Company Claims and Need for Independent Security Verification

Ring’s public assurances about TAKE rest heavily on the company’s own word, and that’s the sticking point EFF keeps circling back to. Verifying those claims independently is still a work in progress rather than a finished process.

Ring’s Promises Versus Independent Verification

Ring maintains that no employee can access footage under TAKE, that it doesn’t keep backups of the keys, and that any decrypted content gets deleted from its servers once processing is finished. Those are meaningful commitments on paper. But EFF notes that the promise carries less weight when routine user actions — like opening an old clip or triggering a smart alert — send the keys straight back to the server, effectively resetting the protection cycle.

Ring told EFF that it “conducts rigorous security reviews of all products before launch” and that “critical components of TAKE’s infrastructure underwent independent security testing prior to launch,” adding that it is “exploring options for further independent review.” EFF’s response is that beyond a white paper, “trust us” is currently the main level of verification the company is offering outside observers, and that opening the full infrastructure to third-party auditors would be the minimum next step to back up those claims with something more concrete than a corporate statement.

None of this makes TAKE meaningless. It’s a real change from a system where Ring had constant, unrestricted access to footage, and it does put a time limit on how long the company holds usable keys. But the gap between that and genuine end-to-end encryption is exactly where the privacy debate over Ring camera encryption is likely to keep playing out — especially as regulators, courts, and privacy advocates continue pressing smart-home companies on how much access they retain, even temporarily, over the video pouring out of millions of front doors.

FAQ

What is Amazon’s Throw Away the Key Encryption (TAKE)?

TAKE is a new encryption method for Ring cameras where encryption keys are temporarily stored in Amazon’s cloud for 24 hours to enable features like video search before the keys are deleted.

Does TAKE provide full end-to-end encryption for Ring videos?

No. TAKE allows Ring temporary access to decrypted videos for up to 24 hours at a time, which differs from true end-to-end encryption, where the service never has access to the keys at all.

Can law enforcement access Ring videos under TAKE encryption?

Law enforcement could potentially compel Ring to retain encryption keys or unencrypted videos, since the company retains temporary access and it remains technically possible for Ring to modify its key-retention practices under legal orders.

Has Ring undergone independent security audits for TAKE?

Ring says it has conducted rigorous internal security reviews and some independent testing prior to launch, but full third-party audit transparency is not yet publicly available.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.