Amazon recently debuted a new feature for its Ring cameras that the company is calling "Local History."Throw Away the Key EncryptionThe plan is to reduce the amount of video content accessible to the company, and consequently, to law enforcement. While it may technically impose a speed bump in accessing full video, it doesn't provide nearly the level of privacy we should expect from video doorbells and security cameras.
TAKE introduces a new method for Ring to manage encryption keys, where the user's device holds its key, and the company temporarily stores encryption keys within its cloud infrastructure. Ring's servers temporarily receive the keys to enable features it claims it cannot offer when a user opts for end-to-end encryption, such as video descriptions, smart alerts, video search,And moreThe system sends a unique code to the user's phone via SMS, which they must enter to access the account. After 24 hours, the code expires and the key is deleted.
This differs from how it operates now, where footage is encrypted in transit and at rest, then decrypted by Ring, which always has access to the footage, to process those features.
Comparatively, this is an improvement over Ring's default settings, as it at least imposes some restrictions on historical footage, but it has some serious flaws worth examining.
Ring Gains Access to Unencrypted Video for a Short Period
Ring has designed its service such that many of its camera features, including smart alerts and video search, require cloud processing to function. Therefore, to provide these features, Ring must decrypt the footage while it is stored on Ring’s cloud servers.
With TAKE, to decrypt footage and offer these features, Ring gains access to footage stored in the cloud for 24 hours. TAKE employs some small measures using secure enclaves to make the base key material harder to directly export, but keys are still released to services that can be modified. With access to the keys, cloud processing takes over and delivers the requested feature to the user. The key is then deleted 24 hours later—until the user wants to watch an old video or use other so-called “smart” features, at which point the keys are sent back to the server.
In practice, this makes the system as a whole barely different from at-rest encryption where the server holds the keys. The client device essentially takes the place of aHardware Security Module (HSM)Including making those keys available to the server whenever they're needed. The final outcome is an enhancement over the current state of affairs, but it's still far from achieving the privacy protections ofEnd-to-end encryption.
The company states that it does not maintain backups of the keys and there is no way for a Ring employee to access footage. It also asserts that any decrypted content is deleted from its servers.
However, this means little when user actions send the keys back to the server. Enabling features like "Video Search" and "Smart Video Descriptions" on the device means that while the footage is inaccessible to Ring, descriptions are readily available to the company. Ring responded, "As Ring continues to expand and strengthen TAKE's protections, video descriptions will be included."
Additionally, account recovery keys are stored in the camera by default. Combined with the fact that video content indices are accessible to the company, TAKE offers no protection against mass surveillance. Law enforcement could request a mass search across cameras for specific terms, then seize cameras of interest, decrypt backups, and use that information to decrypt encrypted videos.
Law Enforcement May Still Seek to Compel Access to Footage
Due to the access and key rotation mechanisms, it is still technically possible for Ring to alter its practices if compelled by law enforcement, similar to other existing at-rest encryption systems where the company holds the keys. For instance, Ring could be ordered to save content encryption keys or unencrypted videos from memory to disk, retaining some access.
In an email to EFF, Ring stated, "By design, under TAKE, Ring will not provide encryption keys or decrypted content. Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring's policy to object to overbroad legal requests." EFF inquired about complying with law enforcement orders to modify practices to turn over or preserve unencrypted video, which is technically feasible, but the company did not address it.
End-to-end encryption maintains user trust as the employing company never has access to the keys, making it impossible for them to access the encrypted content. This also prevents law enforcement from demanding the service retain keys or choose not to rotate them. The level of protection described for TAKE does not offer this.
Ring is responsible for managing this software and its implementation, and beyond a white paper, they offer no other verification to outside observers. While this doesn't resolve issues, the company needs to open its entire infrastructure to third-party auditors to verify its claims. Ring acknowledges this, stating, "Ring conducts rigorous security reviews before launch, and critical components of TAKE's infrastructure underwent independent security testing. We are exploring options for further independent review."
TAKE is not end-to-end encryption, and Ring does not claim it as such. Ring already offers end-to-end encryption as an option.Enabling that by defaultWould provide the actual types of privacy enhancements we all desire from video doorbells.
