Tapo (Rust/Python library) now speaks TP-Link's TPAP protocol

(mihai.dinculescu.dev)

76 points | by faithraven 2 hours ago

4 comments

  • nilamo 8 minutes ago
    I feel like I'm either too dumb to get this, or not the target audience. I don't know what a Tapo is, but it's apparently a library to interact with Tapo devices, whatever that might be. And now it can talk TPAP, whatever that is. TP-Link is mentioned, so I'll guess Routers and move on :)
  • pkilgore 2 hours ago
    I was always taught: Read good books, that's how you'll write.

    I don't even really care AI or human if its written like this. I would rather do anything else than continue reading.

    • IshKebab 2 hours ago
      Hard to disagree. I'm interested, but... the writing sucks.

      And there's no excuse now anyway the latest Opus/Astra models are actually tolerable. Use those if you must.

      • nicce 44 minutes ago
        The point of the writing is thinking what you are about to say from difference perspectives. Now, everything gets average and boring if LLMs are getting used all the time. And they still waste so many words that don't benefit reader in any way.
      • faithraven 2 hours ago
        [flagged]
    • the-grump 10 minutes ago
      Were you not also taught to "say something nice or nothing at all?"

      There's no reason to be this nasty. If you don't like the writing, skip the post.

      For what it's worth, the writing is clear and it gets the point across.

      OP, thank you for doing the work and for sharing it.

  • teravor 1 hour ago
    since GLM 5.2 (perhaps even earlier?) it has been remarkably easy to reverse engineer any closed protocol you want as long as you have a binary. previously, it required so much manual effort as to simply not be worth it 95% of the time.

    now all you need is IDA or Ghidra MCP, a binary and some vague sloppy instructions.

    some more recent models even started instrumenting a running binary (when possible) to enumerate the protocol without being explicitly instructed to, which is even better.

    • Retr0id 1 hour ago
      You don't even need an MCP, I just let the agent write scripts for headless ghidra. The MCPs are fragile and there isn't a whole lot of knowledge about how to use them in the training datasets, whereas there are plenty of ghidra scripts (and proper docs for the APIs).
      • bri3d 13 minutes ago
        I agree! Don't give it away!

        Seriously, though, the popular Ghidra MCP is really badly architected; it's way better to rearchitect it or just script Ghidra directly. With that said, Opus 5.5 seems to have been trained on CoT from the popular Ghidra MCP. This makes it work better, but also makes it even more inefficient if you modify the MCP without changing its name and shape significantly (it will try to make tool calls using the "mainline" format, then have to retry them when they fail).

        Even with Opus 5.5, IMO it's better to just ditch the MCP and let the LLMs eat with bintools and headless Ghidra; with both GLM and Opus this produces significantly more efficient results than the popular MCP. On the other hand the IDA Pro MCP is much better architected and seems to be pretty good.

      • teravor 1 hour ago

            > there isn't a whole lot of knowledge about how to use them in the training datasets
        
        if you include a SKILL.md for the MCP (or just dump it into the prompt) it's not a problem.

        I don't use Ghidra but IDA Pro MCP works extremely well for me for all manner of tasks. for example, some software likes to call home for license checking (and I wish to run it with networking denied to it). it no longer does.

        • bri3d 17 minutes ago
          The IDA Pro MCP is substantially better than the most popular Ghidra MCP, for what it's worth.
        • Retr0id 58 minutes ago
          Sure, you can do that, but in my experience it's usually best to let agents do the things they already know how to do.
    • faithraven 1 hour ago
      Without admitting to anything, I was surprised by how little time it took to add support for the new protocol to the library. And I didn't even need an MCP server.
  • faithraven 2 hours ago
    Author here. tapo is an unofficial Rust client library for TP-Link Tapo devices (plugs, lights, hubs, cameras), with a Python wrapper built on the same crate. It is not affiliated with TP-Link.

    The short version: since late 2025, firmware updates have made Tapo devices refuse third-party clients unless you turn on a "Third-Party Compatibility" switch in the Tapo app. The switch works by bringing back the older login, KLAP. With it off, devices speak an undocumented protocol called TPAP, which logs in with SPAKE2+ (RFC 9383). The library now speaks TPAP, so the switch can stay off.

    The part I found most interesting is the security difference. A recorded KLAP login can be used to test password guesses offline. With SPAKE2+ it can't, and learning the password later doesn't decrypt sessions captured earlier. So the "compatibility" switch is really a security downgrade, and TP-Link's own FAQ says enabling it "may reduce the security of your devices".

    Not everything works with the switch off yet: some cameras, such as a C210 on firmware 1.5.2, still need it on.

    Happy to answer questions about the protocol work or the library.

    • the-grump 7 minutes ago
      One thing to keep an eye out for is a communication from TP link telling you to stop using their name.

      Great work!

    • tclancy 1 hour ago
      This is awesome, thanks for the work. I wish I'd come across it sooner.
    • mindslight 1 hour ago
      I have a handful of old TP-Link wifi switch devices, but I haven't kept up on the play by play developments. I just know at some point newer ones stopped working with that access method (and I haven't bought any since).

      Is KLAP that old local-network UDP protocol with "XOR encryption" ? Or is that something else?

      Does using TPAP with your library still require connecting the devices to their "cloud" (warning: surveillance!) ? Or does your library effectively restore the local-only workflow of never allowing the devices Internet access, and controlling them locally ?

      • tecleandor 35 minutes ago
        Note that KLAP, afaik, is only for the TAPO range of devices. Those are mostly cameras, doorbells, sensors, robot vacuums, and the like.