← Back to context

Comment by faithraven

9 hours ago

Author here. tapo is an unofficial Rust client library for TP-Link Tapo devices (plugs, lights, hubs, cameras), with a Python wrapper built on the same crate. It is not affiliated with TP-Link.

The short version: since late 2025, firmware updates have made Tapo devices refuse third-party clients unless you turn on a "Third-Party Compatibility" switch in the Tapo app. The switch works by bringing back the older login, KLAP. With it off, devices speak an undocumented protocol called TPAP, which logs in with SPAKE2+ (RFC 9383). The library now speaks TPAP, so the switch can stay off.

The part I found most interesting is the security difference. A recorded KLAP login can be used to test password guesses offline. With SPAKE2+ it can't, and learning the password later doesn't decrypt sessions captured earlier. So the "compatibility" switch is really a security downgrade, and TP-Link's own FAQ says enabling it "may reduce the security of your devices".

Not everything works with the switch off yet: some cameras, such as a C210 on firmware 1.5.2, still need it on.

Happy to answer questions about the protocol work or the library.

We appreciate you posting your work and engaging in the discussion. But it's a no-no on HN to post comments that are generated (including polished or translated) by LLMs or other text-generation tools.

See https://news.ycombinator.com/item?id=47340079.

Please write all comments by hand, from your own thoughts, and resist the temptation to copy+paste anything from a chatbot or translation tool.

  • The article is also AI, I recognize its style from a mile away. I don't mind it super much when it's yapping like this about what it did for the tasks that I myself gave it, but I don't enjoy it for reading pleasure on the off-times.

  • Totally AI-generated, sure. But saying "No AI edits" at all is going way too far, IMO. Taken to its logical extreme, that even bans using a spell-checker. And what about non native English speakers? Is it really wrong for them to use a translation tool so they can participate?

    I mean, it's y'all's site, you can do what you want. But FWIW, I think making that too much of an absolute "bright line" is a net negative for HN.

    • > to its logical extreme, that even bans using a spell-checker

      But we're not taking it to that extreme. We're fine with using LLMs for checking of spelling and grammar, and for suggesting improvements to text you've authored yourself, and then using your own human judgement to apply the changes back into your text.

      What we are saying is: don't copy+paste something from an LLM chatbot or translation tool into the Hacker News comment box and submit it.

      > making that too much of an absolute "bright line" is a net negative for HN

      What matters is the outcome. HN is for thoughtful conversation between humans, and that's what people expect when they come here. If regular HN users have that unpleasant sensation that comes upon realizing that what you're reading was generated by a machine rather than being authored by a thoughtful human, the commenter made a negative contribution to HN.

I've built the same code but in swift. I've come to the exact same conclusions that you have on the protocol. I got Claude Code to implement TPAP compatibility solely by interacting with my local plugs, looking at the shape of responses and RFC 9383 to figure out it was SPAKE2+. It took a bit of time to figure out the last bit: that the SHA-1 of the password, then PBKDF2 with the plug's salt, split into two halves; a context of "PAKE V1" plus both sides' random numbers; empty identities

Awesome work. Here is hope this will also help improve local access to Tapo devices in Home Assistant.

Great work!

I assume because it has Python wrapper, the HomeAsstant integration can make use of it soon?

One thing to keep an eye out for is a communication from TP link telling you to stop using their name.

Great work!

I have a handful of old TP-Link wifi switch devices, but I haven't kept up on the play by play developments. I just know at some point newer ones stopped working with that access method (and I haven't bought any since).

Is KLAP that old local-network UDP protocol with "XOR encryption" ? Or is that something else?

Does using TPAP with your library still require connecting the devices to their "cloud" (warning: surveillance!) ? Or does your library effectively restore the local-only workflow of never allowing the devices Internet access, and controlling them locally ?

  • That XOR protocol is a different one, and older than anything in the article. It is the original TP-Link Smart Home protocol used by the Kasa line (HS100, HS110 and similar): JSON on port 9999, obfuscated with an XOR autokey cipher, with no authentication at all.

    Tapo devices never spoke it. Their original protocol was an AES passthrough over HTTP, KLAP replaced that in 2023, and TPAP is the newest. As far as I know, newer Kasa hardware and firmware moved to KLAP as well, which would explain why your access method stopped working on the newer ones. My library only covers Tapo devices; for Kasa, python-kasa is the one to look at.

    On the cloud: the devices do have to be set up through the phone app with a TP-Link cloud account. Once set up, though, most functions of most devices can be used locally through the library, with neither the devices nor the library having internet access. The main catch is credentials: if you change the account password, for example, the devices need to be online for a little while to pick up the new one.

    • Ah, okay. Thanks for the clarification. I actually do have some Tapo cameras as well - being used with the official cloud service, subscription fee and all - because they solve a problem (and aren't observing my day to day life). So if/when I end up taking over digital ownership of those, I look forward to using your library.

  • Note that KLAP, afaik, is only for the TAPO range of devices. Those are mostly cameras, doorbells, sensors, robot vacuums, and the like.