Tapo (Rust/Python library) now speaks TP-Link's TPAP protocol
faithraven
129 points
61 comments
October 06, 2026
Related Discussions
Found 5 related stories in 89.8ms across 8,687 title embeddings via pgvector HNSW
- ActivityPub over ATProto (2023) albuic · 57 pts · July 10, 2026 · 43% similar
- TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years BadChemical · 74 pts · July 17, 2026 · 43% similar
- Signing TLS handshakes inside a TPM bschaatsbergen · 15 pts · September 06, 2026 · 43% similar
- Protobuf has LSP support. You're welcome theanonymousone · 137 pts · August 16, 2026 · 42% similar
- The Rust on ESP Book AlexeyBrin · 15 pts · July 25, 2026 · 42% similar
Discussion Highlights (6 comments)
faithraven
Author here. tapo is an unofficial Rust client library for TP-Link Tapo devices (plugs, lights, hubs, cameras), with a Python wrapper built on the same crate. It is not affiliated with TP-Link. The short version: since late 2025, firmware updates have made Tapo devices refuse third-party clients unless you turn on a "Third-Party Compatibility" switch in the Tapo app. The switch works by bringing back the older login, KLAP. With it off, devices speak an undocumented protocol called TPAP, which logs in with SPAKE2+ (RFC 9383). The library now speaks TPAP, so the switch can stay off. The part I found most interesting is the security difference. A recorded KLAP login can be used to test password guesses offline. With SPAKE2+ it can't, and learning the password later doesn't decrypt sessions captured earlier. So the "compatibility" switch is really a security downgrade, and TP-Link's own FAQ says enabling it "may reduce the security of your devices". Not everything works with the switch off yet: some cameras, such as a C210 on firmware 1.5.2, still need it on. Happy to answer questions about the protocol work or the library.
pkilgore
I was always taught: Read good books, that's how you'll write. I don't even really care AI or human if its written like this. I would rather do anything else than continue reading.
teravor
since GLM 5.2 (perhaps even earlier?) it has been remarkably easy to reverse engineer any closed protocol you want as long as you have a binary. previously, it required so much manual effort as to simply not be worth it 95% of the time. now all you need is IDA or Ghidra MCP, a binary and some vague sloppy instructions. some more recent models even started instrumenting a running binary (when possible) to enumerate the protocol without being explicitly instructed to, which is even better.
nilamo
I feel like I'm either too dumb to get this, or not the target audience. I don't know what a Tapo is, but it's apparently a library to interact with Tapo devices, whatever that might be. And now it can talk TPAP, whatever that is. TP-Link is mentioned, so I'll guess Routers and move on :)
mplewis
Reads like AI slop.
ltbarcly3
We should encourage each other to divest from hardware suppliers who are unfriendly to it's users. TP-Link should be publishing specifications to make it as easy as possible to interact with the hardware you purchase, not trying to maximize lock in or force you into a closed ecosystem. The transaction should be you give them money, they give you hardware and as much information as they reasonably can to use it effectively and safely, repair it later if necessary, etc. We have become used to having to take whatever we get as though consumers have no power in the market. Stop buying TP-Link hardware until they treat us as paying customers. Encourage other people to stop also. Don't buy hardware from manufacturers who treat you like crap, and don't participate in attempts to 'make it work' by reverse engineering it while they release firmware to break those attempts again and again. Stop funding your own opposition!