Product1 publisher3 min readPublished
Ring holds a copy of your camera key for 24 hours to keep video search running
Amazon's Throw Away the Key setting stops Ring from holding video keys permanently. Instead its cloud borrows a camera's key for up to 24 hours at a time so smart alerts, video search and descriptions keep working.
The Product Desk · Product desk

What happened
- Amazon has launched Throw Away the Key Encryption, or TAKE, for Ring cameras, a change to key handling meant to cut how much video the company can reach and therefore what law enforcement can get from it.
- Under TAKE the user's device has its own key while Ring holds keys temporarily in its cloud infrastructure, and the company deletes that cloud copy after 24 hours.
- Ring's existing arrangement encrypts footage in transit and at rest and then decrypts it on Ring's side, where the company always has access to the footage in order to process its features.
- Ring says it keeps no backups of the keys, that no Ring employee can access footage, and that any decrypted content is deleted from its servers.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint The ceiling on how private a Ring camera can be is set by which features Ring wants to run in its cloud, because smart alerts and video search cannot work without a decryption step on Ring's servers.
- decision Owners now choose between features and key custody, and the household that checks old clips daily gives up most of the 24-hour benefit without ever seeing a setting change.
- exposure A searchable index the company can read, plus recovery keys sitting in the hardware, put old footage within reach of anyone who can both query the index and take the camera.
- contradiction Ring's account and Techdirt's describe the same system in incompatible terms, so whether the company can produce anything depends entirely on whether a key happens to be resident when the request lands.
Someone opens the app on a Thursday to find the clip of the van that pulled up on Tuesday. That tap sends the camera's key back to Ring's servers, because the stored video cannot be read without it [5]. The 24 hours starts over.
So 24 hours is the length of one loan, not a ceiling on how long Ring's servers hold a usable key. The key is deleted 24 hours after it arrives, and every view of old footage resets that clock, so a household that opens old clips more often than once a day keeps a working key on Ring's side continuously [17].
The window exists because of the feature list. Ring built the service so that smart alerts and video search run in its cloud, and providing them requires decrypting footage stored on those servers [6]. Ring says that under end-to-end encryption it cannot offer video descriptions, smart alerts, video search and more [3]. Techdirt calls TAKE an improvement on what Ring ships by default, because it puts at least some restriction on historical footage [16].
Users leave the default on, then tap a four-day-old clip when a parcel goes missing. That second behaviour is the one that returns the key [5].
The text layer around the video sits outside all of it. Video descriptions are available to the company, and so are indices of video contents [9]. Asked about that capability, Ring told Techdirt: "As Ring continues to expand and further strengthen TAKE's protections, video descriptions will be included" [10]. Techdirt's scenario joins that to the recovery keys stored in the camera: a mass search across cameras for a term, seizure of the cameras of interest, decryption of the account backup, then the videos [12].
Ring's own description is narrower. "By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content," the company said in an email to EFF [15]. Techdirt's counter is that the client device is doing the job of a hardware security module, handing keys to the server whenever they are needed. On that reading the system as a whole is barely different from encryption at rest with server-held keys [7]. TAKE does use secure enclaves to make base key material harder to export directly, and keys are still released to services that can be modified [13].
The decision an owner faces is smaller than the cryptography. It comes down to whether you used video search or acted on a smart alert in the last month, and whether the thing you worry about is a warrant aimed at your household or Ring's standing access to everything you record. Cloud features plus worry about standing access is the combination where TAKE beats the default. If you never touch those features, end-to-end encryption is already available and costs you nothing you use. If a warrant is the worry, Techdirt notes that Ring could be ordered to save content encryption keys or unencrypted video from memory to disk [14]. Ring's statement to Techdirt did not include a timeframe for bringing descriptions inside TAKE [19].
What to watch
- Whether Ring extends TAKE to cover video descriptions and the searchable index of video contents, and on what schedule.
- Whether any order tests Techdirt's scenario of compelled retention of content encryption keys or plaintext during the window Ring controls.
- Whether Ring keeps full end-to-end encryption available as a separate setting alongside TAKE.