Ring has introduced Throw Away the Key Encryption (TAKE), a new default video-encryption architecture designed to retain cloud-based camera and AI features while reducing the period in which Ring can decrypt customer footage. Built on the open Messaging Layer Security (MLS) standard, TAKE assigns unique rotating keys to recordings; Ring can use a temporary cloud-held copy to process requested features, then deletes the key within 24 hours of completing that processing. A phased global rollout is planned to begin in September 2026.
Ring said it will be unable to provide TAKE-protected video in response to valid government requests once the relevant keys have been deleted, though it may still supply non-video account information and users can voluntarily share recordings. Customers can instead enable end-to-end encryption, which offers stronger protection but disables Shared User video access and certain cloud-dependent capabilities; keys may be recovered through nearby-camera authentication, passphrases, or cloud backups. Ring Verify, a separate digital seal for validating exported cloud-video integrity, is not compatible with end-to-end-encrypted recordings.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Ring announced Throw Away the Key Encryption (TAKE), a default video-encryption model using rotating keys temporarily retained in a secure cloud enclave for up to 24 hours to support enabled cloud features before deletion. Ring said TAKE is built on the Messaging Layer Security standard and users can alternatively select end-to-end encryption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcetechrepublic.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.