Ring's New TAKE Encryption Standard: What It Does and Why It Matters

Ring, Amazon's smart home division, announced on August 26, 2026 that it is adopting a new encryption standard called TAKE (Throw Away the Key Encryption) as the default for video encryption and user control across its cloud features. The standard will gradually roll out to customers beginning September 2026 and will become the default worldwide, though users can still manually select end-to-end encryption (E2EE) instead of TAKE if they prefer (TechCrunch).
TAKE uses a rotating set of encryption keys temporarily stored in the cloud, accessible only to Ring, to power features that require the company to briefly decrypt and process user video. Once a processing request is completed, Ring deletes the keys within 24 hours. In other words, Ring holds the digital "key" to unlock your encrypted video only long enough to run a specific task, then throws it away. This lets Ring offer cloud-dependent capabilities such as Smart Alerts, which notify users when people, vehicles, or packages appear in a camera's field of view, without holding ongoing access to decrypted video (About Amazon).
The standard was built on Messaging Layer Security (MLS), an open messaging standard developed by the IETF (the Internet Engineering Task Force, the body that sets many core internet protocols). Ring's technical whitepaper describes MLS as the foundational layer for TAKE's key management and rotation scheme (TechCrunch). MLS was originally designed for end-to-end encrypted group messaging and has been adopted in protocols like the Matrix federation and Apple's iMessage group chats. Its selection here brings a well-voted IETF standard into a consumer IoT context for the first time.
TAKE also introduces a multi-path key recovery model. Users who lose access to their device can authenticate by standing near their Ring cameras to recover encryption keys. They can also use a passphrase, cloud-based backups, another approved device, or passkeys to regain account access. This addresses a long-standing tension in E2EE systems: strong encryption that locks out the legitimate user when credentials are lost.
Ring already encrypts videos stored in its cloud at rest (while stored) and in transit (while being transmitted) by default (Ring Privacy). The company's existing E2EE option, which protects video and audio with a user-created passphrase, has been available as a manual opt-in feature. As of February 2021, the Electronic Frontier Foundation noted that Ring's E2EE was not enabled by default and required users to turn it on manually (EFF). TAKE, by contrast, will be the default standard worldwide.
The design sits between two extremes: fully end-to-end encrypted video that bars Ring from offering any cloud-side intelligence features, and provider-side access that compromises the encryption model entirely. TAKE's rotating, time-limited keys let Ring process video for features like Smart Alerts while bounding the window during which decryption is possible. The 24-hour deletion window and the MLS-based rotation are the mechanisms intended to enforce that bound.
Whether that bound holds in practice will depend on implementation details Ring has not fully disclosed, including how key rotation intervals relate to the 24-hour deletion window, how access to temporary keys is audited, and whether third-party security researchers will be able to evaluate the system independently. The MLS foundation is public and well-scrutinized, but TAKE's application layer on top of it is, at this point, described only in Ring's own whitepaper and announcements.
For the broader smart home industry, the move sets a reference point. Consumer IoT cameras have lagged messaging apps in encryption maturity, largely because cloud-side processing and end-to-end encryption have been treated as mutually exclusive. TAKE is an attempt to reconcile them. If the approach holds up to independent review, it could become a template other device manufacturers face pressure to match.
Ring users who want the strongest available guarantee can still opt for E2EE manually. What changes is the baseline: the default experience now includes a structured encryption model with time-limited key access, rather than leaving the strongest encryption as an opt-in that most users never enable. The September 2026 rollout will determine how transparently the implementation matches the announced design.


