Tech Policy

Amazon's Ring Encryption Feature Falls Short of True Privacy Protection

Ring's new Throw Away the Key Encryption (TAKE) system limits how long the company holds decryption keys, but security experts say the approach still leaves significant privacy gaps compared to genuine end-to-end encryption.

5 min read
Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

Amazon's Ring division has introduced a novel encryption approach for its camera systems dubbed Throw Away the Key Encryption (TAKE), designed to restrict the volume of video material accessible to the corporation and consequently to law enforcement agencies. Despite offering some procedural obstacles to obtaining complete video content, the technology fails to provide the robust privacy safeguards expected from residential security cameras and video doorbells.

Under TAKE, encryption keys reside on the user's device initially, with Ring maintaining temporary copies within its cloud systems. The company's servers obtain these keys temporarily to deliver features including video descriptions, intelligent alerts, and video search capabilities, then removes the key after 24 hours. This contrasts with Ring's current approach, where footage undergoes encryption during transmission and storage, then gets decrypted by Ring—which maintains perpetual access—to enable these processing functions.

While representing a step forward from Ring's existing default configuration by imposing some constraints on stored video, the system contains substantial vulnerabilities warranting examination.

Ring Gets Access to Unencrypted Video for a Short Period

Ring has structured its platform such that numerous camera capabilities, particularly intelligent alerts and video search, depend on processing within its cloud infrastructure. Delivering these functions requires Ring to decrypt footage while maintaining it on Ring's servers.

Through TAKE, Ring obtains access to cloud-stored footage for 24 hours to decrypt it and provide these capabilities. The system incorporates modest protections using secure enclaves to make base key material more resistant to direct extraction, yet keys remain accessible to modifiable services. Once the keys are available, cloud processing executes and transmits the requested capability to the user. Following 24 hours, the key gets removed—until the user accesses archived video or engages other intelligent features, triggering the keys to return to the server.

Functionally, this renders the overall system barely distinguishable from encryption-at-rest arrangements where the server maintains the keys. The client device essentially performs the function of a hardware security module (HSM), including making those keys accessible to the server as circumstances require. The outcome constitutes an enhancement over current conditions, yet remains substantially inferior to the privacy assurances provided by end-to-end encryption.

Ring asserts it maintains no key backups and Ring personnel lack the capability to view footage. The organization additionally maintains that any decrypted material gets purged from its infrastructure.

However, this assertion carries limited weight when user activities transmit the keys back to the server. Enabling features such as "Video Search" and "Smart Video Descriptions" for the device proprietor means that while Ring cannot observe the footage, the company readily obtains the descriptions. When asked about this capability, Ring communicated that, "As Ring continues to expand and further strengthen TAKE's protections, video descriptions will be included."

Furthermore, account recovery keys remain stored within the camera by default. Combined with the reality that content indices currently remain accessible to the company, TAKE provides no safeguard against widespread surveillance. Law enforcement might execute a broad search across cameras for particular keywords, then pursue additional information by confiscating cameras from property owners, decrypting account backups, and leveraging that data to decrypt protected videos.

Law Enforcement May Still Seek to Compel Access to Footage

Given the mechanisms governing access and key rotation, Ring could theoretically modify its current procedures if pressured by law enforcement, mirroring how other encryption-at-rest systems function when the provider maintains the keys. For instance, Ring might receive a directive requiring them to preserve content encryption keys or unencrypted videos from memory to storage, enabling them to sustain some degree of access.

In correspondence with the Electronic Frontier Foundation, Ring stated: "By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content. With TAKE, Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring's policy to object to overbroad legal requests." The EFF specifically inquired about the feasibility of complying with law enforcement directives to alter existing procedures to deliver or retain unencrypted video, which appears technically feasible, though Ring declined to address this question.

End-to-end encryption maintains credibility with its user population because the organization implementing it never possesses access to the keys under any circumstance, rendering it impossible for the organization to reach the encrypted material. This equally prevents law enforcement from requiring the service to preserve keys or refrain from rotating them. TAKE does not furnish this category of protection.

Fundamentally, Ring controls this software and its deployment, and beyond a technical document, external observers receive only assurances without verification mechanisms. While this doesn't resolve the underlying concerns, Ring should minimally grant third-party auditors complete access to its infrastructure to substantiate its assertions. Ring appears to concur, having informed us that, "Ring conducts rigorous security reviews of all products before launch and critical components of TAKE's infrastructure underwent independent security testing prior to launch. We are exploring options for further independent review."

TAKE represents something other than end-to-end encryption, where Ring would never obtain access to the keys, and the company appropriately refrains from characterizing it as such. Ring presently provides end-to-end encryption as an option, and implementing it as the standard setting would deliver the genuine privacy enhancements residential security cameras ought to provide.

Source: Electronic Frontier Foundation (Deeplinks / Updates)

Source: Electronic Frontier Foundation (Deeplinks / Updates) · Reporting supplemented by The Silicon Ledger staff.