logoalt Hacker News

faithraven • today at 4:53 PM • 1 reply • view on HN

That XOR protocol is a different one, and older than anything in the article. It is the original TP-Link Smart Home protocol used by the Kasa line (HS100, HS110 and similar): JSON on port 9999, obfuscated with an XOR autokey cipher, with no authentication at all.

Tapo devices never spoke it. Their original protocol was an AES passthrough over HTTP, KLAP replaced that in 2023, and TPAP is the newest. As far as I know, newer Kasa hardware and firmware moved to KLAP as well, which would explain why your access method stopped working on the newer ones. My library only covers Tapo devices; for Kasa, python-kasa is the one to look at.

On the cloud: the devices do have to be set up through the phone app with a TP-Link cloud account. Once set up, though, most functions of most devices can be used locally through the library, with neither the devices nor the library having internet access. The main catch is credentials: if you change the account password, for example, the devices need to be online for a little while to pick up the new one.


Replies

mindslight • today at 8:21 PM

Ah, okay. Thanks for the clarification. I actually do have some Tapo cameras as well - being used with the official cloud service, subscription fee and all - because they solve a problem (and aren't observing my day to day life). So if/when I end up taking over digital ownership of those, I look forward to using your library.