ProductNot yet confirmed elsewhere1 publisher2 min readPublished
Ring's New Default Encryption Puts a Clock on What It Can Hand Police
Ring's new TAKE encryption deletes its own copy of video keys within 24 hours, reshaping what law enforcement can legally obtain from the cloud.
The Product Desk

What happened
- Ring is making its new TAKE encryption the default for all customers, subscription or not, starting with a gradual rollout in September.
- TAKE rotates the encryption key covering Ring footage every five minutes rather than using one static key.
- The rollout comes after a year of scrutiny over Ring's law enforcement ties and the privacy concerns raised by its Search Party AI feature.
Why it matters
- exposure Legal requests for footage older than 24 hours now return only encrypted files that Ring itself says it can no longer decrypt, since key copies are deleted daily with no backups.
- precedent Making TAKE the default for every customer, not just subscribers, sets a public technical benchmark other cloud-connected home camera services will now be measured against.
- cost Customers who exhaust every recovery option, from phone backup to passphrase to camera-based recovery, permanently lose access to their own footage under the no-backup design.
The mechanism matters more than the name. TAKE is built on Messaging Layer Security, an open IETF standard [6]. Under that design, a single camera's footage cycles through 288 separate five-minute keys over one day [4][14], each one purged by a database that keeps no backups [8][17].
That timing, not the encryption itself, is the real shift. A request that reaches Ring within a day of recording could in theory still be paired with a live key, but a request for footage from last month arrives at an encrypted file with no key anywhere left to open it, according to Ring [8][17]. Ring's own framing acknowledges the limit: the company says it will hand over only non-video information and encrypted files, according to spokesperson Sam McGee [3], while conceding this does not fully remove the privacy trade-off of a cloud-based camera [13]. It is not end-to-end encryption, because Ring temporarily holds a copy of every key inside an AWS Nitro Enclave, unlocked only when its own attestation process confirms a request came from software it approved [5][15][16]. Key delivery is push only, so Amazon's servers cannot pull a key from a device without the customer asking first [9].
The commercial logic behind the compromise is plain. Before TAKE, Ring decrypted footage in the cloud to run its smart features after encrypting it only in transit and at rest [12]. Ring wants to keep selling AI powered search, package alerts and video descriptions, features that still require the cloud to process footage [1]. Full end-to-end encryption, which Ring already offers on newer cameras [7], breaks those features outright because Ring never holds a key at all. TAKE lets Ring claim it limits police access while keeping the processing pipeline its subscription business depends on.
Making TAKE the default for every customer, subscription or not, sets that compromise as the baseline for the largest home camera network with direct law enforcement partnerships [2][11]. Any other cloud video product now making a similar privacy claim has a concrete bar to clear: a stated deletion window and a documented enclave, not just a promise.
What to watch
- Whether independent security researchers can verify Ring's AWS Nitro Enclave and attestation claims beyond Ring's own white paper.
- Whether law enforcement agencies test the 24-hour deletion window by requesting older footage and how Ring responds in practice.
- Whether Amazon extends TAKE-style key deletion to other cloud video products, such as Blink, given the privacy benchmark it now sets.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption22
- Hype gap+24
- Incentives78
- Confidence52
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
TAKE still supports smart alerts for people and packages, AI-powered video search, and video descriptions.
- [2]
Ring's new TAKE encryption is rolling out gradually starting in September and will become the default encryption for all Ring customers, regardless of subscription.
- [3]
Ring says that under TAKE it will only be able to provide non-video information and encrypted video files in response to requests.
- [4]
With TAKE, content encryption keys change for every five minutes of footage.
- [5]
TAKE is not end-to-end encryption; unlike E2EE, where Ring never has the keys and cannot process video, Ring temporarily holds copies of the keys under TAKE.
- [6]
TAKE was developed using Messaging Layer Security, an open standard from the Internet Engineering Task Force.
- [7]
Newer Ring cameras that encrypt on-device support both TAKE and full end-to-end encryption and let users switch between them; older cameras that encrypt at cloud ingress only support TAKE.
- [8]
Each key is permanently deleted after 24 hours, a window Ring's Sam McGee said allows for processing current cloud-based features, and no backups are kept.
- [9]
Ring says key delivery is push only, meaning Amazon's servers cannot force devices to hand over keys remotely; only the customer can request one, and viewing older footage requires an authorized device to send the keys back to Ring for that session.
- [10]
If a customer loses access to their device, Ring offers recovery methods accessible only to the customer, including cloud backup via phone, a passphrase, a passkey, another authorized device, and camera-based recovery; if all fail, the encrypted content cannot be accessed.
- [11]
TAKE arrives during a year of intense scrutiny for Ring driven by its ties to law enforcement and the privacy implications of its AI-powered Search Party feature.
- [12]
Before TAKE, footage captured by Ring cameras was encrypted in transit to the cloud and at rest, then decrypted for Ring to process for smart features.
- [13]
Ring's new encryption does not completely eliminate the privacy trade-off of cloud-based cameras.
- [14]
A single Ring camera's footage cycles through 288 separate five-minute encryption keys over a 24-hour period.
- [15]
Ring's copy of the keys is managed inside an AWS Nitro Enclave, with Ring's access restricted by access controls, cryptography and hardware isolation; Ring claims there is no persistent storage and no way for a Ring employee to access it.
- [16]
The stored keys can only be unlocked through cryptographic attestation proving the enclave is running the exact software image Ring approved, and the enclave releases a temporary key only when an enabled service requests it.
- [17]
Ring's white paper describes deletion as continuous: as each key ages past 24 hours, the Cloud Member Management Service ratchets the key derivation hierarchy forward and discards the original, the CMMS database is configured with no backups, and the deletion is designed to be irreversible.
Sources
1 independent publisher whose own reporting we read for this story.
- theverge.comRing says its new encryption limits what it can give police
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Law Enforcement Data RequestsFollow
- Consumer Camera PrivacyFollow
- Confidential ComputingFollow
- Encryption and Key ManagementFollow
- Cloud vs Edge InferenceFollow