Commenters discussed a Rust/Python client for TP-Link Tapo devices gaining support for TPAP, with the author (faithraven) explaining that recent firmware forces third‑party clients off unless a "Third‑Party Compatibility" switch enables an older KLAP login. Faithraven argued TPAP uses SPAKE2+ (RFC 9383) and is cryptographically stronger: recorded KLAP sessions can be tested offline against password guesses, while SPAKE2+ prevents learning past sessions even if the password is later compromised. Faithraven also noted some devices (e.g., a C210 on firmware 1.5.2) still require the compatibility switch, so coverage is not universal. John_strinlai and tecleandor added background on the Tapo brand and device types; mindslight asked whether TPAP restores local‑only control or still requires cloud connectivity.
Responses ranged from praise and gratitude (tclancy, the-grump) to nitpicks about writing style (IshKebab, nilamo) and concerns about potential legal pushback (the-grump). A technical side debate focused on reverse‑engineering tooling: teravor and bri3d described how modern LLMs and MCPs can speed protocol discovery, while Retr0id and faithraven recommended scripting headless Ghidra rather than relying on fragile MCPs; bri3d and teravor singled out IDA Pro’s MCP as better‑designed. Overall opinion split between enthusiasm for the project and differing views on tooling and presentation, with practical questions about cloud dependency and device compatibility left as topics for follow‑up.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.