upvote
We appreciate you posting your work and engaging in the discussion. But it's a no-no on HN to post comments that are generated (including polished or translated) by LLMs or other text-generation tools.

See https://news.ycombinator.com/newsguidelines.html#generated and https://news.ycombinator.com/item?id=47340079.

Please write all comments by hand, from your own thoughts, and resist the temptation to copy+paste anything from a chatbot or translation tool.

reply
The article is also AI, I recognize its style from a mile away. I don't mind it super much when it's yapping like this about what it did for the tasks that I myself gave it, but I don't enjoy it for reading pleasure on the off-times.
reply
Totally AI-generated, sure. But saying "No AI edits" at all is going way too far, IMO. Taken to its logical extreme, that even bans using a spell-checker. And what about non native English speakers? Is it really wrong for them to use a translation tool so they can participate?

I mean, it's y'all's site, you can do what you want. But FWIW, I think making that too much of an absolute "bright line" is a net negative for HN.

reply
> to its logical extreme, that even bans using a spell-checker

But we're not taking it to that extreme. We're fine with using LLMs for checking of spelling and grammar, and for suggesting improvements to text you've authored yourself, and then using your own human judgement to apply the changes back into your text.

What we are saying is: don't copy+paste something from an LLM chatbot or translation tool into the Hacker News comment box and submit it.

> making that too much of an absolute "bright line" is a net negative for HN

What matters is the outcome. HN is for thoughtful conversation between humans, and that's what people expect when they come here. If regular HN users have that unpleasant sensation that comes upon realizing that what you're reading was generated by a machine rather than being authored by a thoughtful human, the commenter made a negative contribution to HN.

reply
I've built the same code but in swift. I've come to the exact same conclusions that you have on the protocol. I got Claude Code to implement TPAP compatibility solely by interacting with my local plugs, looking at the shape of responses and RFC 9383 to figure out it was SPAKE2+. It took a bit of time to figure out the last bit: that the SHA-1 of the password, then PBKDF2 with the plug's salt, split into two halves; a context of "PAKE V1" plus both sides' random numbers; empty identities
reply
Great work!

I assume because it has Python wrapper, the HomeAsstant integration can make use of it soon?

reply
Awesome work. Here is hope this will also help improve local access to Tapo devices in Home Assistant.
reply
This is awesome, thanks for the work. I wish I'd come across it sooner.
reply
One thing to keep an eye out for is a communication from TP link telling you to stop using their name.

Great work!

reply
I have a handful of old TP-Link wifi switch devices, but I haven't kept up on the play by play developments. I just know at some point newer ones stopped working with that access method (and I haven't bought any since).

Is KLAP that old local-network UDP protocol with "XOR encryption" ? Or is that something else?

Does using TPAP with your library still require connecting the devices to their "cloud" (warning: surveillance!) ? Or does your library effectively restore the local-only workflow of never allowing the devices Internet access, and controlling them locally ?

reply
That XOR protocol is a different one, and older than anything in the article. It is the original TP-Link Smart Home protocol used by the Kasa line (HS100, HS110 and similar): JSON on port 9999, obfuscated with an XOR autokey cipher, with no authentication at all.

Tapo devices never spoke it. Their original protocol was an AES passthrough over HTTP, KLAP replaced that in 2023, and TPAP is the newest. As far as I know, newer Kasa hardware and firmware moved to KLAP as well, which would explain why your access method stopped working on the newer ones. My library only covers Tapo devices; for Kasa, python-kasa is the one to look at.

On the cloud: the devices do have to be set up through the phone app with a TP-Link cloud account. Once set up, though, most functions of most devices can be used locally through the library, with neither the devices nor the library having internet access. The main catch is credentials: if you change the account password, for example, the devices need to be online for a little while to pick up the new one.

reply
Ah, okay. Thanks for the clarification. I actually do have some Tapo cameras as well - being used with the official cloud service, subscription fee and all - because they solve a problem (and aren't observing my day to day life). So if/when I end up taking over digital ownership of those, I look forward to using your library.
reply
Note that KLAP, afaik, is only for the TAPO range of devices. Those are mostly cameras, doorbells, sensors, robot vacuums, and the like.
reply
And plugs. Don't forget the plugs! Everyone loves their smart plugs :)
reply