SINGAPORE, 29 AUG 2026 — Ring has announced a new default encryption scheme for its cameras called Throw Away the Key, or TAKE, under which the company deletes its copy of your video keys after 24 hours. It is an improvement. It is also, by design rather than by omission, not end-to-end encryption.
Ring's own whitepaper sets out the distinction in some detail, and very little of the coverage has picked it up.
How TAKE actually works
Under TAKE, each camera encrypts its video with keys that change frequently. Ring receives a copy of those keys and unlocks them inside a secure enclave, where access is constrained by hardware isolation and access controls so the keys can only be used to power features active on the account. After 24 hours, Ring permanently deletes its copy.
The scheme is built on Messaging Layer Security, an IETF standard, which is a serious foundation rather than a bespoke design. The 24-hour window is deliberate. It is the period Ring needs to process footage for the cloud features you have switched on, such as Video Search and Video Description.
The key comes back
Ring's own worked example shows what happens after the 24 hours are up.
A week later, you open the app to watch a clip. Ring no longer holds the key, so your app sends Ring the key it needs to prepare the video for playback — optimising quality for your connection, in Ring's example. Ring then deletes that key again when the processing finishes.
None of that is a flaw. It is how the system is meant to operate. TAKE is a system in which Ring's access to your video is time-boxed and purpose-bound, and can be re-established whenever a cloud feature needs it, at your device's initiative. It is not a system in which Ring is structurally incapable of seeing your footage.
That distinction is the whole difference between TAKE and end-to-end encryption, and Ring states it plainly: under E2EE, Ring does not receive the keys at all, there is nothing for it to delete, and Video Search, Video Description and Shared Users stop working. E2EE remains available. It is not becoming the default, because it breaks the features.
What this means for legal process
Most reporting frames TAKE as limiting what Ring can hand to police. That is broadly right, and the limit has a specific shape.
Within the first 24 hours of a recording, Ring holds a usable key. That is also the window in which a recent incident is most likely to generate a preservation request. After 24 hours Ring's position does change: a request would produce encrypted footage and account metadata, not viewable video.
There is a second boundary that the whitepaper draws and the coverage has not. The document states that its protections describe video stored on Ring's infrastructure under a subscription. It explicitly does not cover video that customers choose to share — through share links, through Ring's video donation tool, or through Neighbors. Historically, sharing is exactly how footage has reached law enforcement: not by compelling Amazon, but by asking the owner. TAKE does not touch that pathway, and no encryption scheme could.
The pathway Ring rebuilt
That exclusion reads differently once you know what Ring did with the sharing route.
In January 2024, after sustained criticism from privacy groups, Ring shut down Request for Assistance, the Neighbors feature that let police departments solicit footage from users in an area. It was presented as a reversal on police access, and it was.
It did not last. Ring subsequently introduced Community Requests, reported as running in partnership with Axon, the body-camera and taser manufacturer, and functionally mirroring the programme it had retired. The mechanism is the same: an agency asks, users decide, and footage that is voluntarily shared leaves the account.
The two announcements sit side by side. Ring has strengthened the cryptography on video that stays on its servers, and it has restored the route by which video leaves them with the owner's consent. Both moves may be sincerely meant. Only the cryptography is what this week's news covers, and a reader who takes TAKE as a response to the surveillance criticism has matched an answer to the wrong question.
Your key may be stored on the doorbell
Encryption schemes fail at recovery, and Ring has published its recovery matrix, where one row deserves attention.
TAKE supports camera-based recovery: your key is stored on the Ring camera itself, and a new phone brought near it restores access over Bluetooth or Wi-Fi. Ring says this is on by default for TAKE on cameras with compatible hardware, and that it can be disabled.
Under E2EE, that method is not available at all. The asymmetry is deliberate and it is the correct call, because the camera is the one component of the system mounted in a publicly accessible place. Anyone weighing TAKE against E2EE should know that the default configuration puts a copy of the key on the hardware bolted to the outside of the building.
The other methods — iCloud Keychain, Google Blockstore and Drive, approval from an existing device, a passphrase, a passkey — work in both modes, and the passphrase is the universal fallback.
How to read a cryptography announcement
The useful habit here is the one we applied when Signal added automatic key verification: read what the mechanism cannot do, not what the name suggests.
TAKE is a meaningful upgrade on the previous default, in which Ring's cloud simply had access to video with no time limit. Deleting keys on a rolling basis is better than not deleting them, an enclave-bound key is better than an ambient one, and building on MLS rather than something invented in-house is the right instinct.
The name promises more than the mechanism delivers. Ring discards the key, and your app returns one whenever a cloud feature calls for it. If your threat model includes Amazon itself, or a legal order served inside the processing window, the setting you want is E2EE — and you will have to choose it, accept the loss of Video Search and Video Description, and note that the recovery option that stores a key on your camera goes away with it.
That trade may well be worth making. It is a different one from what the announcement describes.