deniz.in

Markets

Weather

Loading weather

· via TechCrunch

Ring makes TAKE encryption the default, trading end-to-end for cloud smart features

Ring's new TAKE standard uses rotating, auto-deleted cloud keys to enable features like Smart Alerts without full end-to-end encryption, and rolls out worldwide from September.

Ring makes TAKE encryption the default, trading end-to-end for cloud smart features

What Ring announced

Amazon's smart home brand Ring has adopted a new encryption standard called TAKE — short for "Throw Away the Key Encryption" — and made it the default for video encryption and user control across its cloud features, according to TechCrunch. The company announced the change on Wednesday, describing it as a way to protect user privacy while keeping cloud-dependent features available.

The motivation, as Ring frames it, is a trade-off. Traditional end-to-end encryption secures video but blocks features that require Ring's servers to read the footage, such as video search, video description and shared trusted users. TAKE is Ring's attempt to serve both goals at once.

How TAKE works

According to TechCrunch, the standard relies on a rotating set of encryption keys that are held in the cloud temporarily. Ring can access those keys only to run features a user has actively enabled, and once a request is completed the keys are deleted within 24 hours.

That temporary access is what allows Ring to decrypt and process video server-side. The flagship example is Smart Alerts, which notifies users when people, vehicles or packages appear in a camera's field of view. "With TAKE, Ring delivers the intelligent features you love and rely on, like Smart Alerts, and then throws away and deletes the encryption key," Ring said in a blog post quoted by TechCrunch. "Only you retain the keys to your video."

The design is not built from scratch. Amazon's white paper, cited by TechCrunch, says TAKE is based on Messaging Layer Security (MLS), an open standard developed by the Internet Engineering Task Force, repurposed here for key management in a camera context rather than its usual messaging domain.

Recovering keys without a support desk

Key loss is the classic weakness of any system that keeps encryption keys on user devices, and TAKE appears to address it with several recovery routes. According to TechCrunch, users who lose a device and buy a new one can authenticate simply by standing near their Ring cameras to recover their encryption keys. Alternatives include a passphrase, cloud-based backups, another approved device, or passkeys.

Rollout and the opt-out

TAKE will roll out gradually to customers from September and will be the default standard worldwide, TechCrunch reports. Users who prefer strict end-to-end encryption can still select it manually instead of TAKE.

The timing is worth noting. Ring has drawn sustained criticism in recent months over its "Familiar Faces" feature, which uses facial recognition to identify visitors. In June, TechCrunch notes, a class action lawsuit accused Amazon of storing images of passersby without their consent.

Why it matters

Default settings are the real privacy decision for most users, since the overwhelming majority never change them. By making TAKE the default, Ring is choosing a middle path: it keeps the door open for server-side intelligence — the features Amazon differentiates on — while imposing a self-set limit on how long it can hold decryption keys.

Privacy-conscious users will note what TAKE is not. End-to-end encryption means the vendor cannot read user content at all; TAKE means Ring can read it, briefly, whenever a cloud feature needs it. Anyone who wants the stronger guarantee must opt in to end-to-end encryption themselves and give up the smart features in the process. The design effectively makes convenience the default and maximal privacy the option.

That said, the deletion guarantee and the reliance on an open standard like MLS give the approach more structure than a simple trust-us promise. If the rollout works as described, it could set a template that other smart home vendors follow — and it gives security researchers something concrete to audit once the keys, and the clock on their deletion, start moving in production.

  • #smart-home
  • #encryption
  • #privacy
  • #security
  • #amazon

Related posts