logoalt Hacker News

faithraven • today at 1:55 PM • 2 replies • view on HN

Author here. tapo is an unofficial Rust client library for TP-Link Tapo devices (plugs, lights, hubs, cameras), with a Python wrapper built on the same crate. It is not affiliated with TP-Link.

The short version: since late 2025, firmware updates have made Tapo devices refuse third-party clients unless you turn on a "Third-Party Compatibility" switch in the Tapo app. The switch works by bringing back the older login, KLAP. With it off, devices speak an undocumented protocol called TPAP, which logs in with SPAKE2+ (RFC 9383). The library now speaks TPAP, so the switch can stay off.

The part I found most interesting is the security difference. A recorded KLAP login can be used to test password guesses offline. With SPAKE2+ it can't, and learning the password later doesn't decrypt sessions captured earlier. So the "compatibility" switch is really a security downgrade, and TP-Link's own FAQ says enabling it "may reduce the security of your devices".

Not everything works with the switch off yet: some cameras, such as a C210 on firmware 1.5.2, still need it on.

Happy to answer questions about the protocol work or the library.


Replies

tclancy • today at 3:12 PM

This is awesome, thanks for the work. I wish I'd come across it sooner.

mindslight • today at 3:10 PM

I have a handful of old TP-Link wifi switch devices, but I haven't kept up on the play by play developments. I just know at some point newer ones stopped working with that access method (and I haven't bought any since).

Is KLAP that old local-network UDP protocol with "XOR encryption" ? Or is that something else?

Does using TPAP with your library still require connecting the devices to their "cloud" (warning: surveillance!) ? Or does your library effectively restore the local-only workflow of never allowing the devices Internet access, and controlling them locally ?

➕ show 2 replies