← The Signal Report Work with me

Report 184 · Luxury Home Security

What “encrypted” means on a security camera

Almost every camera box says “encrypted,” often with “bank-grade” or “AES-256” attached. The word covers at least three different promises, and only one question separates them: who holds the key. The clearest public case study is the Federal Trade Commission's 2023 action against Ring, where the court order itself draws that line in plain text.

Encryption is easy to sell because it sounds absolute. The cipher almost never fails. What fails is everything around it: who can ask the system to decrypt, and whether the person asking is really you. That is why a camera can be “encrypted” in every honest sense of the word and still let strangers watch your bedroom.

Three promises hiding in one word

In transit means the video is scrambled on its way from the camera to the company's servers and from the servers to your phone. It stops someone sniffing your Wi-Fi or the network in between. It says nothing about what happens once the video arrives.

At rest means the stored clips are scrambled on the company's disks. It protects against a stolen drive or a misconfigured storage bucket. But the company holds the key, because its own systems have to decrypt the video to play it back to you, analyze it, or share it. Anyone inside the company with the right access can see the footage.

End-to-end means the video is encrypted with keys that live only on your devices, so the company stores footage it cannot read. This is the only one of the three that takes the company out of the list of people who can watch.

“Bank-grade” and “AES-256” name the lock, not who has the key. A box that lists only the cipher hasn't told you which of these three you are buying.

The case that shows the difference

In May 2023 the FTC sued Ring in federal court in Washington, D.C. (Case No. 1:23-cv-1549). The FTC filed the complaint together with a stipulated settlement, and the court entered the order on 16 June 2023, and Ring agreed to pay $5.8 million, which the FTC later sent out as more than $5.6 million in refunds through 117,044 PayPal payments. One thing to keep straight: the order says Ring “neither admits nor denies any of the allegations in the Complaint.” What follows are the FTC's allegations, not findings of fact.

The complaint describes two separate failures, and encryption at rest would not have fixed either of them.

Failure one was the insiders. The FTC alleges that before September 2017 Ring gave every employee, and hundreds of Ukraine-based contractors, full access to every customer video, which were “stored unencrypted on Ring's network.” It alleges that between June and August 2017 one employee viewed thousands of recordings from at least 81 female users, searching for cameras with names like “Master Bedroom,” and that Ring did not catch it by any technical means. A co-worker reported him. The complaint also says Ring did not encrypt customers' video data at rest until August 2019.

Here is the point most coverage skipped. Suppose Ring had encrypted those videos at rest in 2017. The employee would still have been looking at them through Ring's own tools, which decrypt the video for anyone the system trusts. Encryption at rest keeps the disk safe. It does nothing about the people the company lets through the front door, because the company holds the key.

Failure two was the attackers. The complaint says that between January 2019 and March 2020 more than 55,000 U.S. customers had their devices compromised through credential stuffing and brute-force attacks, meaning attackers logged in with reused or guessed passwords. For at least 910 accounts, the attackers went further, watching stored video or live streams or viewing profiles. Some used two-way audio to threaten families and children. The FTC faults Ring for not adopting defenses like multi-factor authentication sooner.

Encryption of any kind on the server is irrelevant to that attack. A password thief who logs in as you is handed your video, decrypted, exactly as you would be. The defense against that is authentication: unique passwords, a second factor, and blocking repeated login attempts.

The order puts the key in writing

The settlement is worth reading for one detail. It requires “Encryption in transit and at rest of all Covered Home Security Recordings in Defendant's control.” That is the baseline. But then, in its definition of a reportable breach, the order says a “Covered Incident” does not include any case where “the Covered Home Security Recordings were encrypted and the encryption key was not also accessed or acquired by an unauthorized person.”

And its rules on access controls, logging and staff training carve out workers who can reach only encrypted data “without the ability to decrypt” it. In other words, the order treats encrypted data as harmless only when the key stays out of the wrong hands. That is the whole lesson, written by a regulator: encryption is a key-management question, not a cipher question.

The order also requires multi-factor authentication (or a documented equivalent) for employees and contractors who reach the video stores, and it requires Ring to offer it to customers as an option. Those requirements answer the two failures. The encryption clause does not.

What end-to-end costs you

Ring now offers optional end-to-end encryption. Its support page says that when it is on, “your video recordings are encrypted with keys that only you control,” and “no one else, including Ring services, can access your encrypted content.” It is the strongest of the three promises, and it is not free.

Ring's own list of features that stop working includes Shared Users, Alexa and Fire TV integration, ring.com viewing, Familiar Faces, Smart Alerts, Video Search, Video Descriptions, Bird's Eye View, Virtual Security Guard and third-party integrations. Anything that needs Ring's servers to look at your video has to go, because the servers can no longer look. Lose your recovery options and the footage is gone too: “By design, Ring cannot access or help recover access to your end-to-end encrypted videos.”

For a large property, that list matters more than it would in an apartment. Shared users are how a house manager, a spouse traveling separately, or a security contractor sees the cameras. Third-party integrations are how a camera talks to the rest of an estate system. End-to-end encryption can be exactly right for interior cameras in private rooms and a poor fit for perimeter cameras that other people need to watch. That is a design decision, and it belongs to the owner, not the default settings.

Ring's privacy page also describes a middle setting it calls TAKE, “Throw Away the Key Encryption.” Ring says it keeps video encryption keys “for 24 hours” to run cloud features, then “only you hold the key to your videos.” Ring says it is rolling this out gradually and will make it the default once rollout finishes. On Ring's description, that narrows the window in which the company can read a clip to one day. It is a vendor description; I have not seen an independent audit of it.

Why this beat cares

I help design the AI security systems for a veteran-owned (SDVOSB) home-security company run by fellow veterans. I do not own that company and earn nothing from this link. Full policy here.

AI analytics sharpen this tradeoff. A cloud model that recognizes faces or describes a scene has to see the video in the clear. Ring's own feature list shows it: Familiar Faces, Smart Alerts and Video Descriptions are on the not-available side of end-to-end encryption. Every “smart” feature a client asks for is a decision about who else is allowed to look. Anyone who has worked military communications learns the same thing about radios: the crypto is only as good as the control over who holds the keys.

What to ask before you buy

  • “Encrypted in transit, at rest, or end to end?” Make them name which, for live view and for stored clips separately.
  • “Who can decrypt my video, and when?” Staff, contractors, AI pipelines, law-enforcement requests. If the company can, ask what controls and logs sit on that access.
  • “Which features stop working with end-to-end on?” A vendor that publishes the list, as Ring does, is being straight with you.
  • “Is multi-factor authentication available, and can I require it for everyone with access?” In the Ring case, passwords, not ciphers, were the door the attackers used.
  • “If I lose my phone, how do I get my footage back?” With true end-to-end encryption, the honest answer involves a recovery phrase you keep yourself.

What I could not confirm

These are allegations. Ring settled without admitting or denying the complaint. I describe what the FTC alleged and what the order requires, not proven facts about Ring's conduct.

I have not tested any product. Ring's end-to-end and TAKE descriptions come from Ring's own pages as published today, and Ring notes some product names have changed. Whether a stolen password alone can unlock end-to-end video depends on the device-enrollment details Ring describes; I have not verified that independently.

Ring is the example, not the outlier. I use it because a federal court record exists. I make no claim about how any other brand handles keys.

The signal

“Encrypted” is a true word that answers the wrong question. In transit protects the wire, at rest protects the disk, and only end-to-end takes the company out of the audience. The Ring case shows that insiders and password thieves walk right past the first two, and the court order itself says encrypted data is only safe when the key is. Ask who holds the key, ask what you give up to hold it yourself, and turn on the second factor either way.

Sources

  1. Federal Trade Commission, Complaint for Permanent Injunction and Other Relief, FTC v. Ring LLC, No. 1:23-cv-1549 (D.D.C.), Document 1, filed 31 May 2023. (PRIMARY. Read in full. Source of the allegations: all-employee and Ukraine-based contractor access before September 2017; “stored unencrypted on Ring's network”; the employee who viewed recordings of at least 81 female users, June to August 2017, detected by a co-worker; no encryption of video at rest before August 2019; the 55,000-customer credential-stuffing and brute-force compromises, January 2019 to March 2020, and the 910 accounts with further access.)
  2. Federal Trade Commission, Stipulated Order for Injunction and Monetary Judgment, FTC v. Ring LLC, Document 12, filed 16 June 2023. (PRIMARY. Read in full. Source of “neither admits nor denies”; the “Covered Incident” encryption-key exclusion quoted verbatim; the “without the ability to decrypt” carve-outs; the multi-factor authentication requirements; “Encryption in transit and at rest”; the $5,800,000 judgment.)
  3. Federal Trade Commission, “FTC Says Ring Employees Illegally Surveilled Customers, Failed to Stop Hackers from Taking Control of Users' Cameras,” press release, 31 May 2023; and “FTC Sends Refunds to Ring Customers…,” press release, 23 April 2024. (Source of the $5.8 million settlement amount and the refunds of more than $5.6 million via 117,044 PayPal payments.)
  4. Ring, “Using video end-to-end encryption,” support article, accessed 8 October 2026. (Vendor documentation. Source of the quoted descriptions of end-to-end encryption and recovery, and the lists of available and unavailable features.)
  5. Ring, “Privacy” page, accessed 8 October 2026. (Vendor documentation. Source of the TAKE description: keys kept “for 24 hours,” gradual rollout, planned default.)

Scope note: this report explains what encryption claims on consumer security cameras do and do not cover, using a public federal court record and the vendor's own published documentation. It evaluates no product's actual security, contains no instructions for attacking any device or account, and is not a substitute for a qualified security designer assessing a specific property. Disclosure: the author helps design AI security systems for a veteran-owned home-security company, as stated in the body of this report, and does not own that company.

Onur Oncer
Onur Oncer

U.S. Army combat veteran (Counter-IED / Electronic Warfare), peer-reviewed researcher in microwave spectroscopy, and founder & CEO of Shroombiosis. Consults on laboratory operations, AI, and supplement formulation.

← All reports