ELSEIF
Your brief EB
456 stories from 139 feeds 679 clusters Refreshed 2 minutes ago next pull 22:46

SECURITY Signal 539 2 feeds carried it

Ring switches all cameras to TAKE encryption limiting cloud and police access to footage

Ring’s new default encryption method, TAKE, restricts Amazon and law enforcement from accessing stored video while preserving cloud-based features.

WHY IT MATTERS

Engineers building or integrating IoT cameras must now account for a key-rotation model that deletes decryption keys after 24 hours. The trade-off between cloud functionality and data sovereignty shifts, requiring updates to recovery workflows and compliance documentation.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

TAKE encryption becomes the default on all Ring cameras, replacing older cloud-ingress encryption.

02

Decryption keys rotate every five minutes and are permanently deleted after 24 hours, preventing persistent access.

03

Cloud-based features remain available, but older footage requires user-initiated key delivery from an authorised device.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

Ring’s TAKE encryption introduces a time-limited key retention model that restricts both Amazon and law enforcement from accessing stored video. The system generates unique encryption keys for every five-minute segment of footage, storing them in an AWS Nitro Enclave. After 24 hours, these keys are permanently deleted, leaving only the user’s authorised devices with the ability to decrypt older footage. This design preserves cloud-based features like AI search and smart alerts while reducing the window during which Ring can comply with legal requests.

The technical implementation relies on cryptographic attestation and hardware isolation to enforce access controls. Keys are only released to the enclave when it proves it is running Ring-approved software, and no persistent storage or backups are maintained. However, the 24-hour retention window is explicitly tied to the processing needs of current cloud features, suggesting future functionality may require adjustments to this timeline. Engineers integrating with Ring’s API or building recovery tools must now handle key rotation and user-initiated key delivery, adding complexity to device management and data recovery workflows.

TAKE does not provide full end-to-end encryption (E2EE), which remains an option on newer cameras. Unlike E2EE, where Ring never holds decryption keys, TAKE allows the company to process video for cloud features but limits its ability to retain or share that data. This compromise addresses privacy concerns without sacrificing functionality, but it also means Ring retains some control over the encryption infrastructure. For users, the shift introduces new recovery methods, such as passphrases or authorised devices, but also creates a single point of failure if all recovery options are lost.

The change reflects broader industry tensions between privacy and cloud-based services. By adopting an open standard (Messaging Layer Security) and publishing a white paper, Ring signals a move toward transparency, though the system’s effectiveness depends on the integrity of the AWS Nitro Enclave and the enforcement of access controls. For engineers, the key takeaway is the need to adapt to a model where data sovereignty is time-bound and recovery is user-dependent, rather than relying on persistent cloud access.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 2 feeds.

ORDERED BY FIRST SEEN
The Verge Ring says its new encryption limits what it can give police Open ↗
Slashdot Ring Says New Encryption Limits What It Can Give Police Open ↗