Amazon’s smart home division Ring announced Wednesday that it is adopting a new encryption standard called TAKE (Throw Away the Key Encryption) as the default setting for video encryption and user control. The company says the standard lets it protect user privacy without relying on end-to-end encryption, which can restrict features such as video search, video description, and shared trusted users.
TAKE involves using a rotating set of encryption keys that are temporarily stored in the cloud and can only be accessed by the company to power features that users may have active. Once the request is completed, Ring says it will delete the keys within 24 hours. The company explained that this allows it to temporarily decrypt and process users’ videos so it can offer cloud-based features like Smart Alerts, which notify users when people, vehicles, or packages are in the camera’s field of view.
Also read: CISA confirms hackers targeted over 100 US water systems in July — here's what we know
“With TAKE, Ring delivers the intelligent features you love and rely on, like Smart Alerts, and then throws away and deletes the encryption key. Only you retain the keys to your video,” the company said in a blog post.
How TAKE differs from end-to-end encryption
End-to-end encryption (E2EE) ensures that only the user can decrypt their video, but it also prevents Ring from offering cloud-based processing features that require temporary access to the content. TAKE is designed as a middle ground, allowing Ring to process video for specific features while minimizing the window in which decryption keys are available.
Also read: Life360 launches $8 scannable pet tags and 'zoomies alerts' to expand its pet tracking lineup
Amazon’s white paper detailing the standard notes that it was developed using Messaging Layer Security (MLS), an open messaging standard created by the Internet Engineering Task Force. The company says that with TAKE, if a user loses access to their device and buys a new one, they can authenticate themselves by standing near the Ring cameras to recover their encryption keys. Alternatively, users can use a passphrase, cloud-based backups, another approved device, or passkeys to recover their account.
Ring said TAKE will be gradually rolled out to customers from September and will be the default standard worldwide. Users can still manually choose end-to-end encryption instead of TAKE.
Privacy scrutiny and legal challenges
The announcement comes amid ongoing criticism of Ring’s privacy practices. Over the last few months, the company has faced backlash for its “Familiar Faces” feature, which uses facial recognition to identify visitors. In June, a class action lawsuit accused Amazon of storing images of passersby without consent.
Ring has previously faced scrutiny from lawmakers and privacy advocates over its partnerships with law enforcement and the data it collects from its cameras. The introduction of TAKE appears to be an attempt to address some of these concerns by limiting the time decryption keys are available and giving users more control over their video data.
What this means for Ring users
For most Ring users, the shift to TAKE will be fluid, as it is designed to maintain the same cloud features they already use. The key change is that Ring will no longer hold onto the ability to decrypt videos indefinitely — keys are now rotated and deleted within 24 hours.
However, users who prioritize maximum privacy may still prefer end-to-end encryption, which ensures that even Ring cannot access their video content. The trade-off is that E2EE disables features like video search and Smart Alerts that require cloud processing.
The company’s decision to make TAKE the default reflects a broader industry trend toward balancing user privacy with the convenience of cloud-based AI features. As smart home devices become more ubiquitous, the debate over who holds the keys to user data is likely to intensify.
For now, Ring users can expect the gradual rollout of TAKE starting in September, with the option to switch to end-to-end encryption at any time. The company’s ability to rebuild trust with privacy-conscious consumers will depend on how transparently it communicates these changes and whether it follows through on its promise to delete keys promptly.
Disclaimer: This article is for informational purposes only and does not constitute financial, legal, or investment advice. The cryptocurrency and technology markets are volatile and uncertain; readers should conduct their own research before making any decisions.