# Ring Is Giving Your Camera a Better Default

> Ring’s new TAKE encryption shortens how long the company keeps video keys while preserving cloud features. Here is what that protects, what it leaves unchanged, and which setting suits your home.

- **Author:** Kubilay Tunca
- **Published:** 2026-08-30
- **Category:** For Mortals
- **Tags:** Privacy, Smart Home, Encryption, Online Safety
- **Canonical URL:** https://cyber-security-in-plain-english.com/post/mortals/news/ring-take-encryption-better-default

---

A doorbell camera records a peculiar kind of family archive. It catches the parcel left under the chair, the neighbour returning a borrowed ladder, the child who forgot a key, and the ambulance that stopped two houses away. Most clips are dull. Taken together, they still reveal when people arrive, who visits, and how a household moves through its week.

Ring announced a new default for protecting that archive on 26 August 2026. The company calls it Throw Away the Key Encryption, or TAKE. Starting with a phased rollout in September, Ring says TAKE will eventually become the default for customers worldwide, including people without a subscription. The short version is promising: Ring will keep its copy of the key needed to process a recording for no more than 24 hours, then destroy that copy on a rolling basis ([Ring, 26 August 2026](https://www.aboutamazon.com/news/devices/ring-take-encryption)).

That is a meaningful improvement over a cloud service holding continuing access to every stored clip. It also needs a careful reading. TAKE lets Ring process recent recordings for alerts, descriptions, search, and other cloud features, and your app can send a key back later when you ask to play or process an older clip. Ring's optional end-to-end encryption setting remains the stronger choice for people who want the company unable to decrypt their recordings at any point. The right setting depends on which features you value and how much cloud access you are willing to accept.

Here is the useful conclusion before we touch the machinery. Accept TAKE when it reaches your account if you want ordinary Ring features with a better privacy default. Choose end-to-end encryption on a compatible camera when the recording is sensitive enough that losing cloud features is a fair price. In either case, review who shares the camera and where it points, because encryption cannot fix an overly broad view or an old housemate who still has access.

## What Ring announced, and when it applies

Ring's announcement covers video captured by Ring cameras and stored on Ring's infrastructure. According to the company's technical paper dated 26 August 2026, TAKE will roll out gradually, customers will be notified when they can enrol, and full feature compatibility will arrive over the rollout period. The company says both TAKE and end-to-end encryption will be available to supported camera customers regardless of subscription status ([Ring technical paper, 26 August 2026](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf)).

The timing matters. As of 30 August 2026, an announcement that TAKE will begin rolling out in September does not mean every Ring account already has it. A missing menu today tells you little, and a news headline does not change your camera remotely. Wait for the notice in the Ring app, then confirm the setting for each enrolled camera. Ring says recordings keep the protection mode under which they were made, so changing a camera's mode affects new recordings rather than rewriting the old archive.

TAKE replaces Ring's current default once the rollout finishes. Today, Ring encrypts video while it travels to the cloud and while it sits in storage. The service can still decrypt that video to run the features attached to the account. Under TAKE, each camera adds another layer with frequently changing keys, and Ring's copy of those keys has a limited life. [TechCrunch's account of the announcement](https://techcrunch.com/2026/08/26/ring-introduces-a-new-encryption-standard-makes-it-the-default-for-cloud-features/) confirms the practical trade: temporary decryption preserves video search, video descriptions, Smart Alerts, and related cloud processing, while key deletion reduces the period of continuing access.

This distinction sounds fussy until you compare it with a spare house key. Encryption in transit and at rest is like carrying the spare in a locked box and storing that box in a locked cupboard. Good. TAKE adds a rule that the service's spare is destroyed after a day. End-to-end encryption goes further by never giving the service a spare in the first place. Those are three different arrangements even though every one can honestly use the word “encrypted.”

Ring has presented TAKE as a way to keep the features that make a cloud camera convenient without holding an everlasting route into old video. That is a sensible engineering goal. It also explains why TAKE has a 24-hour access window instead of zero access: cloud features need to see a decrypted picture to tell a person from a parcel or to search for a red jacket. The system cannot both inspect an image and remain mathematically unable to inspect it during the same operation.

The default status gives this change its value. Optional privacy switches help the people who know where to find them. A better default reaches the tired parent installing a doorbell at 9 p.m., the shop owner who inherited an account, and the person who has never opened a page called Video Encryption. TAKE does not ask each of them to become a cryptographer before receiving shorter-lived cloud access.

## How the disappearing key works

Imagine that your camera creates a new tiny keyring every five minutes. Your authorised phones, tablets, and web browsers keep the key material they need. Under TAKE, a Ring cloud component joins the camera's encryption group too, but with a narrower job: it can obtain a content key for features active on your account. Ring says that component cannot add members, change the encryption mode, or rewrite the group's access rules on its own ([Ring technical paper, sections 2.3 and 3.1](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf)).

The company built the group system on Messaging Layer Security, an open standard originally designed for encrypted groups whose membership changes. A standard foundation is useful because researchers can study its assumptions and because devices can move to fresh cryptographic states as members join or leave. Ring then added its own camera format, cloud member, permission policy, and deletion design. The open foundation therefore does not make the whole Ring system independently proven. Ring's own extensions still deserve scrutiny.

When the camera records, newer supported models encrypt the picture before it leaves the device. Ring says older models that lack suitable hardware encrypt at the point where video enters its cloud. Both paths use changing keys and the 24-hour deletion rule, but they do not create the same journey. A newer camera sends already encrypted image content across the network. An older one has a short stretch inside Ring's infrastructure before the extra TAKE layer is applied, and those older cameras cannot use Ring's end-to-end mode.

Ring's cloud copy of the key sits behind a service running in an AWS Nitro Enclave. You can picture the enclave as a small locked workroom inside a larger computer. The wider system can ask the workroom to perform an approved task, but the workroom has no ordinary operator login, no persistent disk, and no general network connection. Ring says an enclave releases key material only after proving that it is running the approved software image, then a feature service receives the particular content key needed for its job.

The unlocked video does not remain inside that workroom for every stage. Ring's paper says a platform service performs work such as object detection or video search, with the key confined to the service's encryption software memory and erased after processing. That is a limit worth naming plainly. The enclave protects the root key material and controls release. A feature that must analyse a picture still receives what it needs to analyse that picture. Ring says it is exploring further work that would require those feature services themselves to run inside environments that can prove their identity.

Deletion happens continuously. A key for one five-minute slice ages past 24 hours, the key manager moves its secret forward through a one-way calculation, and the old value is discarded. Ring says the database has no backups from which an expired secret could be recovered. That is better than a nightly cleanup job with a folder of forgotten backups. It also narrows the consequences if someone later reaches the current cloud key state, because old key material should no longer exist there.

Your devices keep their own route to the archive. Suppose you open a week-old clip. The Ring app identifies the key needed for that time and pushes it to the cloud for a playback job such as adapting video to your connection. Ring says the cloud cannot command your app to surrender an old key; the transfer follows an action you chose, and the service discards the supplied key when processing ends. The video then reaches your authorised device, which decrypts it for you to watch.

That last step is why “throws away the key after 24 hours” needs the next sentence. Ring throws away its retained copy. It can receive a temporary copy again when your app requests an older-video operation. This does not erase the improvement. It tells you where control sits: the standing cloud route expires, while an authorised customer device can reopen a route for a requested session.

## What TAKE protects in ordinary life

The easiest way to value TAKE is to imagine a request for a two-week-old porch recording. Ring told [The Verge](https://www.theverge.com/tech/984838/ring-take-encryption-throw-away-the-key-law-enforcement) that, where TAKE is enabled, it could provide basic subscriber information and an encrypted video file in response to valid legal process, but not a usable copy of the video from its own retained keys. The company says it has updated its law-enforcement guidelines to reflect the architecture.

That technical limit is stronger than a promise to refuse improper requests. Policies can change, people can make mistakes, and a company can be compelled to hand over information it possesses. Deleting a necessary key changes what the company possesses. For older recordings that have passed the window without your app supplying a key for a new operation, Ring says the cloud has encrypted files it cannot open by itself.

The improvement also reduces the store of enduring secrets inside a large service. A permanent key library is valuable to anyone who finds a route into it. TAKE replaces that library with a moving window, changing content keys every five minutes and deleting cloud-held material as it expires. No security design removes every route to misuse, but shortening the life of a powerful secret is sound housekeeping. A spare key that ceases to exist tomorrow is a smaller long-term liability than one left in a drawer forever.

Family access becomes more precise as well. Ring's paper says a shared user joins the encryption group at the current state and cannot derive keys for recordings made before the invitation was accepted. Remove that person and the group moves to fresh keys that exclude their device from future content. If this works as described, giving a dog sitter access next Tuesday should not silently open last month's family archive, and removing the sitter should close the door on later clips.

TAKE also creates an activity log for membership and encryption changes. Authorised devices can see events such as a device being added or removed, or end-to-end encryption being switched on or off. Ring describes these events as part of the encrypted group's state, making silent alteration detectable by group members. For an ordinary household, the practical benefit is simple: there should be a place to check whether the devices and people attached to a camera are the ones you expect.

Recovery is designed around the uncomfortable consequence of customer control. If a service destroys its lasting copy, it cannot always rescue you after every key is lost. Ring offers several routes, including an existing authorised device, a recovery passphrase, platform cloud backup, a passkey, and, for compatible TAKE cameras, recovery while physically near the camera. The paper says a complete loss of every recovery method leaves old encrypted content inaccessible, although an account reset lets the camera create new groups for future recordings.

Losing old clips would be painful after a burglary or an accident. Still, recovery that no employee can quietly perform on your behalf is a sign that control has moved closer to you. Save the recovery passphrase somewhere outside the phone that runs the app. A password manager or a paper copy in a safe place is more useful than a screenshot stored only on the same device you may lose.

## What the new default leaves unchanged

TAKE does not stop a camera from recording the pavement, a neighbour's doorway, or everyone who visits your home. It protects stored video from some forms of access. Camera placement decides what enters the archive in the first place. If the view includes more of another person's life than you need to protect your parcel or door, narrow the angle and use privacy zones where the device supports them.

Cloud analysis still happens for enabled features. Ring says Smart Alerts, Video Search, Video Descriptions, and similar services need temporary access to decrypted content. The feature may also produce information about that content, such as a text description or a search index. EFF security and privacy activist Thorin Klosowski told The Verge that TAKE's limits may not cover future-video demands or additional data derived from recordings, including text descriptions ([The Verge, updated 28 August 2026](https://www.theverge.com/tech/984838/ring-take-encryption-throw-away-the-key-law-enforcement)).

That concern deserves more than a footnote. Destroying the key to a video does not automatically destroy a sentence previously produced from it. “Person in a red coat approached the front door at 14:12” can be sensitive even if the underlying picture later becomes unreadable to the cloud. Ring's public paper explains key deletion in considerable detail, but the ordinary user still needs clear controls and retention information for descriptions, alerts, account records, and other information produced around the video.

The 24-hour window remains a real access window. During that period, approved Ring services can obtain keys for features active on the account. TAKE narrows and structures access, according to Ring, but it asks you to trust the company's software, deployment controls, feature services, and account configuration. The company published a technical design; The Verge reported that Ring did not point to an independent evaluation of the full design as of its 28 August update.

Older cameras have another limit. Ring says models that cannot encrypt on the device receive TAKE encryption at cloud ingress. That still adds short-lived keys and deletion, but the footage reaches Ring before the added layer is applied. If on-device encryption matters to you, check the model's support rather than assuming every camera gains identical protection under the shared TAKE name.

Voluntary sharing remains voluntary sharing. Ring's paper says TAKE does not apply to videos you choose to share through tools such as share links, Neighbours, or a video donation feature once those copies move under another party's security arrangements. A protected archive can therefore produce an ordinary shared copy. Before sending a clip, look beyond the event in the centre of the frame for faces, addresses, vehicle plates, and the inside of your home.

Community Requests remain available in regions where Ring offers them. Ring told The Verge that public-safety agencies can request footage for an official investigation, while customers choose whether to respond and an ignored request is not reported back to the agency. TAKE changes what Ring says it can decrypt on its own. It does not prevent you or another authorised user from choosing to share.

Account security also keeps its old importance. Encryption cannot save a recording from someone who signs in as you and adds an authorised device through a valid recovery route. Use a unique password if your account still accepts one, turn on the strongest sign-in protection Ring offers you, secure the email account behind it, and remove devices you no longer use. The clever key machinery assumes that the people and devices admitted to the group belong there.

## TAKE and end-to-end encryption make different bargains

Ring will continue offering end-to-end encryption, usually shortened to E2EE, on compatible cameras. Under that mode, Ring removes its cloud member from the camera's encryption group. New recordings use fresh keys held by your authorised devices, and Ring stores and delivers encrypted video without gaining the means to decrypt it. Switching E2EE off later does not give the cloud keys for recordings made while it was on, according to the technical paper.

The price is feature loss. Ring says Video Search, Smart Video Descriptions, cloud-based Smart Alerts, and other processing that needs decrypted content do not work under E2EE. Shared Users are also unavailable, and enabling E2EE removes them from that camera. Live View, event playback, and 24/7 recording can continue because your device handles the decryption.

For a front-door camera used mainly to see packages and let two family members check alerts, TAKE may be the sensible middle. You keep the shared access and cloud conveniences, while Ring's standing copy of old keys expires. For a camera covering a private office, a source meeting, the inside of a home, or any place where the recording itself could cause harm, E2EE may justify the inconvenience. The setting can be chosen per compatible camera, so one account need not make the same bargain everywhere.

Do not choose from the acronym. Choose from the scene. Ask what this camera can see on its most sensitive day, who needs access, and which cloud features you would genuinely miss. A parcel camera and a nursery camera may sit on the same Wi-Fi network while deserving different answers.

Local recording offers a third arrangement. Some cameras and hubs can store and process footage in the home rather than sending every event to a cloud service. Local systems have their own costs: hardware to maintain, storage that can be stolen or fail, remote access to configure, and updates you must not neglect. They can still be a better fit when you want fewer copies and less routine cloud processing.

CNN's report on the launch described TAKE as Ring's attempt to ease concern around home surveillance while keeping a familiar product experience ([CNN, 26 August 2026](https://edition.cnn.com/2026/08/26/tech/ring-cameras-encryption-update)). That aim explains the middle ground. Most people buy a smart doorbell because they want alerts and easy playback, not because they want a weekend project in key management. A privacy improvement that survives ordinary use can protect more households than a perfect option almost everyone disables.

Calling TAKE a better default gives it due credit without confusing it with the strongest setting. The company gets temporary access for active services; your devices keep durable access; the cloud's retained copy expires. E2EE removes the cloud member and accepts fewer features. Local storage changes where the archive lives. Those plain differences are more useful than arguing over which product gets to use the word “private.”

## A calm five-minute check when TAKE arrives

You do not need to rebuild your home network because Ring announced a new encryption mode. Wait for the app to tell you that your account is eligible, set aside five minutes, and make one pass through the controls. If you manage cameras for an older relative or a small shop, do the review with the person who owns the recordings rather than silently choosing for them.

1. **Confirm the mode on every camera.** Open Ring's Control Center and look for Video Encryption or the enrolment notice named in the app. Check each camera because hardware support and the point of encryption can differ. Record the date and mode if the cameras protect a small business or shared property.

2. **Decide from the view, not from habit.** Keep TAKE where package alerts, shared users, search, or descriptions earn their place. Consider E2EE on compatible cameras that see private rooms, sensitive visitors, children, client material, or any scene whose disclosure would matter more than cloud convenience.

3. **Review people and devices.** Remove old phones, tablets, browsers, housemates, installers, and staff who no longer need access. Check the activity log for additions, removals, and encryption changes you do not recognise. If something looks wrong, secure the account and contact Ring support before treating the log as harmless clutter.

4. **Store a recovery route somewhere separate.** Save the recovery passphrase in a password manager or on paper in a safe place. Confirm that another authorised device or chosen backup works before the phone carrying your only copy gets lost. Avoid leaving the sole recovery record as a screenshot on that phone.

5. **Trim the picture.** Stand outside and look at the live view like a neighbour or visitor would. Adjust the angle and privacy zones so the camera covers the door, gate, vehicle, or parcel area you need without collecting a wider piece of the street or another home by default.

6. **Question cloud features one by one.** Keep the person or package alert you use. Disable search, descriptions, recognition, or sharing features you do not use, where the app offers that control. Fewer active services mean fewer reasons to process decrypted footage and fewer records derived from it.

7. **Update the camera and the account around it.** Install current firmware, protect the Ring account and its email with strong sign-in controls, and check that an old shared password has not become the weak side door. TAKE improves video-key handling; it does not replace ordinary account care.

A household does not need a written camera policy, but one sentence helps: “This camera watches the porch for parcels, and only these three people can see it.” A small business should write down the equivalent, including who can export clips and how long recordings are kept. If the real setup does not match the sentence, fix the setup rather than making the sentence more complicated.

There is also permission to leave well enough alone. If your camera sees only a front gate, TAKE is enabled, account access is tidy, and the view respects the neighbours, you have completed the useful work. Reading the rest of the cryptographic paper will not make the parcel safer.

## The useful lesson behind Ring's new lock

Ring's TAKE design tackles a real cloud problem: a service may need short access to run a feature without needing a permanent route into years of stored video. Rotating keys, restricting a cloud member, and destroying retained key material after 24 hours reduce that route. Making the design a default extends the benefit beyond the small group of customers who hunt through privacy menus.

The limits are equally real. TAKE allows cloud processing during its window, and an authorised app can supply older keys for a requested job. Information derived from a clip may follow different retention rules. Older cameras apply the added encryption at cloud ingress. The full Ring design includes company-built parts and, as of 28 August 2026, Ring had published its own white paper rather than an independent assessment of the complete system.

That balance does not make the feature empty. It makes the choice understandable. TAKE is the better everyday lock for people who want Ring's cloud features. End-to-end encryption is the stronger lock for compatible cameras where preventing Ring from decrypting footage matters more than search, descriptions, shared users, and cloud alerts. Camera placement and account membership remain the walls around both.

The Digital Fortress uses the same rule for every smart-home device: protect the small computer, then limit what it can see and who can reach it. Ring is improving the first part of that bargain. Your part takes five minutes when the notice arrives.

For more calm, practical security guidance, join the newsletter. One email per month, and no panic in your inbox.

## Sources

- [Ring: Ring introduces TAKE, setting a new industry standard for default encryption and control](https://www.aboutamazon.com/news/devices/ring-take-encryption), accessed 2026-08-30
- [Ring: Throw Away the Key Encryption and End-to-End Encryption technical paper](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf), accessed 2026-08-30
- [The Verge: Ring says its new encryption limits what it can give police](https://www.theverge.com/tech/984838/ring-take-encryption-throw-away-the-key-law-enforcement), accessed 2026-08-30
- [TechCrunch: Ring introduces a new encryption standard, makes it the default for cloud features](https://techcrunch.com/2026/08/26/ring-introduces-a-new-encryption-standard-makes-it-the-default-for-cloud-features/), accessed 2026-08-30
- [CNN: Ring hopes new encryption tech will ease surveillance fears around its home security cameras](https://edition.cnn.com/2026/08/26/tech/ring-cameras-encryption-update), accessed 2026-08-30

---

## About the author

Kubilay Tunca — Senior Full Stack Developer and Author. Founded Cyber Security in Plain English to translate complex security concepts into clear, practical advice, and writes the accompanying books on security, privacy, secure development, and AI systems.

## Books by this author

- **The Digital Fortress** — Your Everyday Guide to a Safer Digital Life. A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest. [Amazon](https://buy.cyber-security-in-plain-english.com/digital-fortress) · [Details](https://cyber-security-in-plain-english.com/books/the-digital-fortress)
- **The Anonymity Playbook** — Digital Survival for Whistleblowers, Journalists, Activists, and Everyone Else. A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails. [Amazon](https://buy.cyber-security-in-plain-english.com/anonymity-playbook) · [Details](https://cyber-security-in-plain-english.com/books/the-anonymity-playbook)
- **Secure Software Development** — Practical patterns for building secure software. A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-software-development) · [Details](https://cyber-security-in-plain-english.com/books/secure-software-development)
- **The Secure Harness** — Shipping Production Code with AI Coding Agents. A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-harness) · [Details](https://cyber-security-in-plain-english.com/books/the-secure-harness)
- **The AI Native Engineer** — Build, Evaluate, and Ship AI Systems That Work in Production. Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature. [Amazon](https://buy.cyber-security-in-plain-english.com/ai-native-engineer) · [Details](https://cyber-security-in-plain-english.com/books/the-ai-native-engineer)

Full catalogue with contents and intended audience: https://cyber-security-in-plain-english.com/books

_As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog._
