-
3 minutes, 5 seconds
Ring has announced a significant security upgrade for its camera lineup. Moving forward, Throw Away The Key Encryption will become the default setting on all Ring cameras. This change ensures that end-to-end encryption is automatically applied to video footage, meaning that only the account holder possesses the unique decryption keys. This shift marks a departure from previous configurations, where users had to manually enable the feature. By making it the standard, Ring aims to offer a higher level of privacy out of the box, ensuring that video streams cannot be accessed by unauthorized parties, including Ring itself.
At its core, this method relies on a unique, ephemeral key generated for each video clip. When a video is uploaded from your doorbell or camera, the device creates a single-use encryption key and immediately encrypts the footage with it. The critical step is that this key is then permanently discarded from the device and Ring’s servers. Without the key stored anywhere, the encrypted data is mathematically locked.
This means that even if Ring receives a legal request or a subpoena, there is no way to retrieve the plaintext video. The company simply does not possess the means to decrypt it. Only your own device, which retains a separate private key, can unlock the footage for viewing on your authorized account. This design ensures that the decryption capability rests solely with you, not with Ring or any third party. As a result, the video remains unreadable to anyone else, even if the encrypted files are intercepted or accessed by internal staff.
For users, this encryption model fundamentally shifts the balance of power when it comes to their personal video footage. Because the encryption keys are generated on the device itself and never leave it, the footage is rendered unreadable to anyone who does not possess that specific key. This means that even if a server is breached or data is intercepted during transmission, the video content remains indecipherable gibberish to unauthorized parties. This design effectively neutralizes risks such as data scraping, man-in-the-middle attacks, and internal server vulnerabilities.
Furthermore, the "throw away the key" approach provides a strong guarantee that footage cannot be accessed retroactively. Once the key is discarded, the encrypted data becomes permanently inaccessible, ensuring that no one—including the service provider—can later decrypt it. This offers users a higher degree of control over their personal history, preventing any potential for future unauthorized viewing or misuse of their recordings. The system ensures that privacy is not just a policy, but a mathematical certainty.
The new default will be enabled for all users starting March 15, 2025. No immediate action is required from you—the change happens automatically on the server side, and your existing encrypted data remains fully accessible throughout the transition.
However, to take full advantage of the enhanced privacy guarantees, we recommend you complete one optional step: update your client app to version 4.2 or later. This update ensures your device can generate the ephemeral keys used in the new protocol. Older versions will continue to function, but they will fall back to the previous encryption method, which does not offer throw-away key rotation.
For enterprise and team administrators, we have prepared a detailed migration guide. You can review the technical specifications and rollout schedule on our official documentation page. The rollout will proceed in phases:
No downtime is expected, and you will see a confirmation banner in your dashboard once your account is upgraded.
Comment