Ring, a brand owned by Amazon, is rolling out a new encryption method called TAKE, which stands for "Throw Away the Key Encryption" (or "Jeter la clé de chiffrement" in French). This update is intended to improve user privacy, addressing concerns about data security and surveillance. Ring has built its reputation on selling home security devices, while also being involved in content that sometimes amplifies public fears about mass surveillance. For example, a Super Bowl ad about detecting lost animals was interpreted as an admission that the system can track movement. As a result, Ring needed to make a strong move toward privacy, and TAKE is its response.
TAKE works by managing encryption keys in a novel way. Ring videos are already encrypted during transmission and storage, but now the encryption key is temporarily stored in a secure area of the cloud—similar to a locked safe. This key is used only to activate smart features, such as motion alerts or video search, and is then deleted. Only the user and those they share access with retain the key on their devices. The key passes through a secure component called AWS Nitro, which is protected by strict access controls and hardware isolation. Ring claims that no employee can access the key, and that unlocking it requires a cryptographic confirmation that the software used is exactly the one approved by the company.
While TAKE represents an improvement over previous encryption methods, it is not a complete solution. The Electronic Frontier Foundation (EFF), a digital rights group, has pointed out some limitations. First, Ring keeps a copy of the encryption key in its cloud for 24 hours, the time needed to run its smart features. True end-to-end encryption would require the company to never hold the key, making it impossible for anyone, including legal authorities, to access the data. TAKE reduces the risk, but doesn't eliminate it entirely. Second, the account recovery keys are stored directly on the camera, which could be a vulnerability if the device is physically taken. Ring's marketing materials don't mention this potential weakness.
Finally, there has been no complete independent security audit of TAKE, which is a concern in a field where trust is hard to build. Ring mentions that internal tests and some components have been evaluated by outside experts, and it is looking into future independent reviews. Until then, users must rely on the company's assurances. TAKE is set to become the default encryption method for all Ring devices in the coming months, but its effectiveness will depend on how well it addresses these lingering concerns.
Ring Introduces TAKE Encryption Mode Amid Privacy Concerns
AI-rewritten from original reportingHow it works
encryptionringprivacysurveillancetakeaws
Original sources:
- 🇫🇷Clubic



