EFF says Ring’s new encryption still depends on trust in the company
TAKE limits how long Ring keeps copies of video keys, but it does not provide the same technical separation as end-to-end encryption.
R42 / SUMMARY
The EFF considers TAKE an improvement to Ring cameras’ default protection, but says the system still requires trust in the company because its cloud temporarily receives keys and processes video.
KEY POINTS
- TAKE is rolling out gradually and will become Ring’s default option after the worldwide launch is complete.
- Content keys rotate every five minutes, and Ring’s copy is deleted on a rolling 24-hour window.
- The EFF acknowledges an improvement over the current default but stresses that TAKE is not end-to-end encryption.
- Ring says it cannot provide keys or decrypted video, while the EFF is calling for broader independent auditing.
The Electronic Frontier Foundation published a technical assessment of TAKE, Ring’s new video encryption default, on Friday, September 11. The digital rights group calls the change an improvement over Ring’s current default protection, but argues that it remains well short of end-to-end encryption because company services still receive keys and process recordings for limited periods.
Ring announced Throw Away the Key Encryption, or TAKE, on August 26. The gradual rollout began in September, and the architecture is expected to become the worldwide default when deployment is complete. End-to-end encryption will remain available on compatible devices. The central idea is to preserve cloud features while reducing how long the company can open a recording.
How TAKE manages encryption keys
Under the previous default, videos were already encrypted in transit and at rest, but Ring services could decrypt them to perform features selected by the customer. With TAKE, each camera uses content keys that rotate every five minutes. A copy is temporarily managed by a service running inside AWS Nitro Enclaves, isolated environments that Ring says restrict access through technical controls and provide no persistent storage.
The company’s technical paper defines a rolling 24-hour window. As each key moves beyond that limit, Ring says it deletes the material required to reconstruct it and keeps no backups. If a customer plays an older video or activates a feature that requires fresh processing, the app sends the corresponding key for that session. Ring says this delivery occurs only after a user action and that its cloud cannot request the key on its own.
Implementation differs across hardware generations. Newer compatible cameras encrypt video before it leaves the device and allow customers to choose between TAKE and end-to-end encryption. Older models encrypt content when it reaches Ring’s infrastructure and support TAKE only. The change is available to customers with supported devices regardless of subscription status, although feature availability varies during the rollout.
Why the EFF considers the protection incomplete
The EFF acknowledges that deleting key copies limits Ring’s lasting access to a customer’s video history. Its criticism is that cloud services receive the necessary keys during the first 24 hours and work with decrypted video in memory. For older recordings, a customer action can provide a key again. In the group’s assessment, that architecture still requires trust in software and operational practices controlled by the company itself.
The distinction matters because end-to-end encryption keeps the keys only on authorized devices. In that mode, Ring stores encrypted video but cannot open it, even temporarily. The trade-off is the loss of Shared Users and functions that depend on remote processing, including video search and descriptions. TAKE preserves more convenience; end-to-end encryption more sharply minimizes provider access.
Law enforcement demands and external verification
In a response to the EFF, Ring said TAKE is designed so that the company cannot provide keys or decrypted content and would supply only encrypted files in response to valid legal process. The group is not alleging that Ring already retains such material. Its argument is prospective: because Ring controls the code and temporarily receives keys, a legal order could try to compel a change that preserves keys or future video. According to the EFF, the company did not directly answer that scenario.
Ring also said critical components received independent security testing before launch and that it is exploring options for further outside review. The EFF is calling for a broader audit of the infrastructure. Until additional public verification is available, the practical conclusion is less absolute than either position may suggest: TAKE reduces exposure compared with Ring’s previous default, but it does not remove the trust placed in the provider. For customers who prefer the strongest technical separation and accept losing cloud functions, end-to-end encryption remains the more restrictive option.
Gabriel Silva
Responsible for reporting and writing this story at Rota42.
R42 / FAQ
What is Ring TAKE?
TAKE stands for Throw Away the Key Encryption. It is an architecture in which videos use rotating keys, Ring temporarily keeps a copy for cloud features, and that copy is deleted within 24 hours.
Is TAKE the same as end-to-end encryption?
No. Under TAKE, Ring services can receive keys and temporarily process video. With end-to-end encryption, the company does not receive the decryption keys.
When will TAKE be enabled?
The gradual rollout began in September 2026. Ring says TAKE will become the default for all customers when the worldwide deployment is complete.
Will older Ring cameras support TAKE?
According to Ring’s technical paper, older models can use TAKE with encryption at cloud ingress, but they do not offer end-to-end encryption. Compatible models encrypt on the device itself.
Which option provides more privacy?
End-to-end encryption provides stronger technical separation because Ring does not receive the keys. The trade-off is that Shared Users and features requiring cloud processing are unavailable.