· via The Verge
Ring's TAKE encryption limits what Amazon can hand police as it becomes the default
Ring's TAKE scheme rotates video encryption keys every five minutes and destroys its own copies within 24 hours, so Amazon's cloud can only hand police encrypted files and subscriber data.

Ring has built a new encryption scheme called TAKE, short for "Throw Away the Key Encryption," that limits when and why Amazon's cloud can decrypt customer video. According to The Verge, the feature begins a gradual rollout in September, applies to all customers regardless of subscription, and will become the default encryption for Ring cameras.
How TAKE works
Today, Ring footage is encrypted in transit to the cloud and at rest, but is decrypted so Ring can run smart features such as package alerts and AI-powered video search. TAKE changes that arrangement. Encryption keys rotate every five minutes of footage, and Ring keeps a copy of each key solely to enable processing, then destroys every copy within 24 hours, a window the company says its current cloud features require.
According to a white paper published alongside the announcement, Ring's key copies are held in an AWS Nitro Enclave fenced off with access controls, cryptography and hardware isolation. There is no persistent storage and no path for a Ring employee to reach the keys. The enclave releases a temporary key to an enabled service only after cryptographic attestation proves it is running the exact software image Ring approved.
Deletion is continuous rather than a single event: once a key passes 24 hours, a service Ring calls the Cloud Member Management Service ratchets the corresponding intermediate secret forward using a one-way derivation function, overwriting the original so it cannot be reconstructed. The key database keeps no backups, and Ring says the deletion is irreversible.
Watching older footage works differently too. An authorized device running the Ring app must push its keys back to Ring for that session, and Ring claims key delivery is push-only, meaning Amazon's servers cannot force a device to surrender keys remotely.
TAKE is built on Messaging Layer Security, an open standard from the IETF, although the key-disposal mechanism itself is Ring's own design.
What law enforcement can get
The scheme changes what Ring can hand over. Where TAKE is enabled, Ring will only be able to provide non-video information such as basic subscriber data and encrypted video files in response to valid legal process, spokesperson Sam McGee told The Verge, and the company has updated its Law Enforcement Guidelines to match.
Other programs are untouched. Community Requests, which lets public safety agencies ask customers directly for footage, still depends on customers choosing to respond, and agencies are never notified when a request is ignored. McGee said there is no government backdoor, and that Ring trains its models only on publicly available recordings or on footage from users who gave explicit permission, which can be revoked.
Not the same as end-to-end encryption
Ring describes TAKE as inspired by end-to-end encryption, but the systems differ. With E2EE, Ring never holds keys and cannot process video in the cloud at all. Under TAKE, Ring has access for up to 24 hours and receives keys again whenever a user opens older clips; users can also share keys with others. E2EE remains the stronger privacy option where it is available.
Hardware determines the choice: newer Ring cameras that encrypt on-device can switch between TAKE and E2EE, while older cameras, which encrypt as footage reaches the cloud, support only TAKE.
Losing a device is handled through recovery methods Ring says are accessible only to the customer, including cloud backup via the phone, a passphrase, a passkey, another authorized device and camera-based recovery. If all of them fail, encrypted content is gone for good.
Why it matters
Ring has faced a year of scrutiny over its law-enforcement ties and the privacy implications of its AI-powered Search Party feature. TAKE is a real architectural shift: rather than a standing ability to decrypt any stored footage, Amazon's cloud holds usable keys briefly, inside isolated hardware, and cannot compel devices to re-send them. That materially narrows what can be surrendered under legal process.
The limit is deliberate. Features like Smart Alerts, Video Search, Video Descriptions and Unusual Event Alert rely on models and infrastructure that cannot run on camera hardware, McGee said, and E2EE would break them. Competitors such as Reolink and Eufy take the local route, processing footage on cameras and hubs instead of in the cloud. When The Verge asked whether TAKE had been independently evaluated, Ring pointed to the open MLS standard and its own white paper, meaning the novel part of the system, throwing away the key, rests on trusting the company. TAKE lands as a middle position: genuine constraints on Ring's access, traded for the cloud features the cameras were sold on.
- #ring
- #encryption
- #smart-home
- #privacy
- #cloud