Ring's New 'Throw Away the Key Encryption' (TAKE) Falls Short on True Privacy
Amazon's **Ring** has introduced 'Throw Away the Key Encryption' (**TAKE**) for its security cameras, aiming to limit video access for the company and potentially law enforcement. While **TAKE** offers a marginal improvement over default settings, it fails to deliver the robust privacy protections of true end-to-end encryption, leaving significant gaps for IT security professionals and privacy-conscious users to consider.
Amazon's **Ring** recently debuted a new feature for its cameras, dubbed 'Throw Away the Key Encryption' (**TAKE**). The initiative aims to reduce the volume of video content accessible to the company, thereby potentially limiting its availability to law enforcement. However, while **TAKE** may introduce a minor hurdle to accessing full video content, it doesn't provide the comprehensive privacy that security camera users should demand.
**TAKE** redefines how **Ring** manages encryption keys. Under this system, the user's device holds its primary key, and **Ring** temporarily retains encryption keys within its cloud infrastructure. **Ring**'s servers receive these keys for a limited period to enable features like video descriptions, smart alerts, and video search, which the company states are incompatible with true end-to-end encryption. The keys are then deleted after 24 hours.
This approach differs from **Ring**'s previous default, where footage was encrypted in transit and at rest but decrypted by **Ring** for processing, granting the company perpetual access. While **TAKE** is an improvement by restricting access to historical footage, it harbors significant vulnerabilities.
## Ring Retains Brief Access to Unencrypted Video
Many of **Ring**'s camera features, including smart alerts and video search, rely on cloud processing. To facilitate these functionalities, **Ring** must decrypt the footage while it resides on its cloud servers.
With **TAKE**, **Ring** gains access to footage stored in the cloud for up to 24 hours to decrypt and process these features. Although **TAKE** incorporates some measures using secure enclaves to prevent direct export of base key material, keys are still released to services that can be modified. After processing, the key is deleted 24 hours later. However, if a user wishes to view old videos or utilize other 'smart' features, the keys are re-sent to the server.
In practice, this makes the system's overall privacy posture only marginally better than standard encryption at rest where the server holds the keys. The client device essentially functions as a hardware security module (HSM), making keys available to the server whenever required. The result, while an improvement over the status quo, is far from the privacy protections offered by true end-to-end encryption.
**Ring** states it does not keep key backups and that no **Ring** employee can access footage. The company also claims that any decrypted content is deleted from its servers. However, this offers limited reassurance when user actions can repeatedly send keys back to the server. Furthermore, while **Ring** might not see the video content, the availability of features like 'Video Search' and 'Smart Video Descriptions' implies that descriptions are accessible to the company. **Ring** has indicated that as **TAKE**'s protections expand, video descriptions will be included.
Adding to the concern, account recovery keys are stored on the camera by default. When combined with the company's current access to video content indices, **TAKE** offers little protection against mass surveillance. Law enforcement could request broad searches across cameras for specific terms, then seize cameras of interest from device owners, decrypt account backups, and use that information to access encrypted videos.
## Law Enforcement Could Still Compel Access
Due to the mechanics of access and key rotation, **Ring** could technically be compelled by law enforcement to alter its current practices. This mirrors the situation with other existing encryption-at-rest systems where the company holds the keys. For example, **Ring** could receive an order demanding the preservation of content encryption keys or unencrypted videos from memory to disk, thereby retaining a level of access.
In communication with the EFF, **Ring** stated, "By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content. With TAKE, Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring's policy to object to overbroad legal requests." The EFF specifically inquired about the technical possibility of complying with law enforcement orders to modify existing practice to surrender or preserve unencrypted video, a question **Ring** did not directly address.
End-to-end encryption fosters user trust because the implementing company never possesses the keys, making it impossible for them to access encrypted content. This also prevents law enforcement from demanding the service retain or not rotate keys. As described, **TAKE** does not offer this level of protection.
Ultimately, **Ring** manages the software and its implementation. Beyond a white paper, external observers are largely left with a 'trust us' approach. To mitigate these issues, **Ring** should, at a minimum, open its entire infrastructure to third-party auditors to verify its claims. **Ring** has indicated its agreement, stating, "Ring conducts rigorous security reviews of all products before launch and critical components of TAKEβs infrastructure underwent independent security testing prior to launch. We are exploring options for further independent review."
**TAKE** is not end-to-end encryption, and **Ring** commendably does not market it as such. **Ring** already offers an end-to-end encryption option; making this the default would deliver the substantial privacy improvements that video doorbell users truly desire.