Ring's TAKE Encryption Falls Short of User Privacy Expectations
Amazon's Ring camera service has introduced a new encryption method called Throw Away the Key Encryption (TAKE). The idea behind TAKE is to reduce the amount of video content available to Amazon and potentially law enforcement. However, the EFF argues that this method still doesn't provide the level of privacy users should expect from their security cameras.
TAKE works by storing encryption keys temporarily in Ring's cloud infrastructure. This allows Ring to offer features like video descriptions and smart alerts without needing access to unencrypted footage. But, according to the EFF, this still means that Ring has access to the encrypted content for 24 hours after it's stored in the cloud.
The EFF points out that even with TAKE, law enforcement could still request access to footage by demanding that Ring save encryption keys or unencrypted videos. And while Amazon claims not to keep backups of the keys and doesn't allow employees to access footage, the EFF notes that user actions can send the keys back to the server.
Ring's current default settings already provide some level of protection for historical footage, but the EFF argues that it's still not enough. They recommend that users opt for end-to-end encryption instead, which would prevent Ring from accessing their video content altogether.