Tapo (Rust/Python library) now speaks TP-Link's TPAP protocol
mihai.dinculescu.dev
[hidden]
The transaction should be you give them money, they give you hardware and as much information as they reasonably can to use it effectively and safely, repair it later if necessary, etc.
We have become used to having to take whatever we get as though consumers have no power in the market. Stop buying TP-Link hardware until they treat us as paying customers. Encourage other people to stop also. Don't buy hardware from manufacturers who treat you like crap, and don't participate in attempts to 'make it work' by reverse engineering it while they release firmware to break those attempts again and again. Stop funding your own opposition!
[5 comments hidden]
[hidden]
>Tapo is a brand of TP-Link that offers smart home solutions, such as security cameras, plugs, bulbs, switches, and more.
and TPAP is the "TP-Link Authentication Protocol" which, i believe, is based on 802.1X (https://en.wikipedia.org/wiki/IEEE_802.1X)
[3 comments hidden]
[hidden]
With software like Scrypted or Frigate, I was able to use an Apple TV 4K to get a security feed into my Apple Home with iCloud+. You don’t need to buy Homekit certified product.
[2 comments hidden]
[21 comments hidden]
I don't even really care AI or human if its written like this. I would rather do anything else than continue reading.
[8 comments hidden]
And there's no excuse now anyway the latest Opus/Astra models are actually tolerable. Use those if you must.
[5 comments hidden]
[7 comments hidden]
There's no reason to be this nasty. If you don't like the writing, skip the post.
For what it's worth, the writing is clear and it gets the point across.
OP, thank you for doing the work and for sharing it.
[6 comments hidden]
I can bet author didn't even read his own AI generated text.... I don't have any issue with AI, but it would be nice if people spend time over creating quality stuff.
[4 comments hidden]
Get a life and read something you want to read instead of spilling your bile on somebody sharing their work.
[3 comments hidden]
If you are going to be 'the-grump' you should find something interesting to be grumpy about, nobody wants to hear your "everyone should be nice all the time except me" horse crap. If it isn't intentional trolling you have next to zero insight into what you are actually doing.
[2 comments hidden]
I'll dish it out and dish it back, but I'll never talk down to someone because I don't like how they write or their method of solving problems. We are not all born with the same gifts (or with English as our native tongue).
That's what some here don't seem to understand, that there's a way to put things gently when you're addressing someone to their (virtual) face.
[hidden]
I pasted it into chatgpt with the prompt "analyze the tone of the-grump and check for condescending language and tone. give examples if any." and here is what it says:
Yes, several of the-grump's comments read as condescending. Defending the author from harsh criticism is reasonable, but some of the language used in that defense also talks down to others.
Were you not also taught to "say something nice or nothing at all?"
This is the clearest example. Invoking a childhood manners lesson positions the other person as someone who needs basic correction. You don't see how it's nasty, and then you pile your own nastiness on top.
This is scolding. It treats disagreement as a failure to recognize something obvious, rather than explaining which wording crossed a line. Get a life ... instead of spilling your bile on somebody sharing their work.
This is primarily insulting and contemptuous. Hostility is clearer here than condescension specifically. And who has an interest in your opinion, pray tell.
This is sarcastic and dismissive. "Pray tell" adds a mocking, superior tone, although the remark also echoes the preceding commenter's dismissal of the-grump's opinion. That's what some here don't seem to understand, that there's a way to put things gently...
This presents others as lacking basic interpersonal understanding while placing the speaker in the role of teaching it.[4 comments hidden]
[hidden]
[hidden]
[hidden]
But it's full on the "AI slop" style, a mix of LinkedIn/Online Marketing/Listicle like writing. That it's part of hundreds of thousands of articles, all with the same mechanical style, makes it even more tedious than if it was just some individual blog post here and there.
"Set the scene" paragraphs to add suspense, repeated lists of three or more items, "and, honestly"/"does real load-bearing work" and phrases like this, mic drops after every few paragraphs, writing about mundane stuff like a marketing executive, the list goes on.
This one isn't even one of the really eggregious examples.
[17 comments hidden]
The short version: since late 2025, firmware updates have made Tapo devices refuse third-party clients unless you turn on a "Third-Party Compatibility" switch in the Tapo app. The switch works by bringing back the older login, KLAP. With it off, devices speak an undocumented protocol called TPAP, which logs in with SPAKE2+ (RFC 9383). The library now speaks TPAP, so the switch can stay off.
The part I found most interesting is the security difference. A recorded KLAP login can be used to test password guesses offline. With SPAKE2+ it can't, and learning the password later doesn't decrypt sessions captured earlier. So the "compatibility" switch is really a security downgrade, and TP-Link's own FAQ says enabling it "may reduce the security of your devices".
Not everything works with the switch off yet: some cameras, such as a C210 on firmware 1.5.2, still need it on.
Happy to answer questions about the protocol work or the library.
[5 comments hidden]
Is KLAP that old local-network UDP protocol with "XOR encryption" ? Or is that something else?
Does using TPAP with your library still require connecting the devices to their "cloud" (warning: surveillance!) ? Or does your library effectively restore the local-only workflow of never allowing the devices Internet access, and controlling them locally ?
[2 comments hidden]
[2 comments hidden]
Tapo devices never spoke it. Their original protocol was an AES passthrough over HTTP, KLAP replaced that in 2023, and TPAP is the newest. As far as I know, newer Kasa hardware and firmware moved to KLAP as well, which would explain why your access method stopped working on the newer ones. My library only covers Tapo devices; for Kasa, python-kasa is the one to look at.
On the cloud: the devices do have to be set up through the phone app with a TP-Link cloud account. Once set up, though, most functions of most devices can be used locally through the library, with neither the devices nor the library having internet access. The main catch is credentials: if you change the account password, for example, the devices need to be online for a little while to pick up the new one.
[hidden]
[hidden]
Great work!
[hidden]
[hidden]
[5 comments hidden]
See https://news.ycombinator.com/newsguidelines.html#generated and https://news.ycombinator.com/item?id=47340079.
Please write all comments by hand, from your own thoughts, and resist the temptation to copy+paste anything from a chatbot or translation tool.
[3 comments hidden]
I mean, it's y'all's site, you can do what you want. But FWIW, I think making that too much of an absolute "bright line" is a net negative for HN.
[2 comments hidden]
But we're not taking it to that extreme. We're fine with using LLMs for checking of spelling and grammar, and for suggesting improvements to text you've authored yourself, and then using your own human judgement to apply the changes back into your text.
What we are saying is: don't copy+paste something from an LLM chatbot or translation tool into the Hacker News comment box and submit it.
> making that too much of an absolute "bright line" is a net negative for HN
What matters is the outcome. HN is for thoughtful conversation between humans, and that's what people expect when they come here. If regular HN users have that unpleasant sensation that comes upon realizing that what you're reading was generated by a machine rather than being authored by a thoughtful human, the commenter made a negative contribution to HN.
[hidden]
That's good to hear. I think what I was mostly reacting to above was this:
(including polished or translated)
which to me reads as more of that "bright line" stance I was objecting to. But if that's not the case, then that's cool.
teravor[13 comments hidden]
now all you need is IDA or Ghidra MCP, a binary and some vague sloppy instructions.
some more recent models even started instrumenting a running binary (when possible) to enumerate the protocol without being explicitly instructed to, which is even better.
faithraven[hidden]
Retr0id[10 comments hidden]
teravor[3 comments hidden]
I don't use Ghidra but IDA Pro MCP works extremely well for me for all manner of tasks. for example, some software likes to call home for license checking (and I wish to run it with networking denied to it). it no longer does.
Retr0id[hidden]
bri3d[hidden]
bri3d[6 comments hidden]
Seriously, though, the popular Ghidra MCP is really badly architected; it's way better to rearchitect it or just script Ghidra directly. With that said, Opus 5.5 seems to have been trained on CoT from the popular Ghidra MCP. This makes it work better, but also makes it even more inefficient if you modify the MCP without changing its name and shape significantly (it will try to make tool calls using the "mainline" format, then have to retry them when they fail).
Even with Opus 5.5, IMO it's better to just ditch the MCP and let the LLMs eat with bintools and headless Ghidra; with both GLM and Opus this produces significantly more efficient results than the popular MCP. On the other hand the IDA Pro MCP is much better architected and seems to be pretty good.
cute_boi[4 comments hidden]
Retr0id[hidden]
charcircuit[hidden]
TeMPOraL[hidden]
Starting point was literally original installer copied over from a CD, which I hold on to and dug up from an old hard drive, plus a short prompt asking to make it work. Installing Ghirda and developing a whole framework for patching the binary, as well as substituting DirectDraw with its own DLL shim, was Claude's own invention.
Avamander[hidden]
thedougd[hidden]