•5 min read

SSH and SCP: The Two Tools Every Developer Should Actually Understand

SSH and SCP: The Two Tools Every Developer Should Actually Understand

If you've spent any time working with servers, you've likely typed ssh into a terminal without thinking too hard about it. But when you get locked out at 2 AM or file transfers keep failing, knowing the mechanics of SSH (Secure Shell) and SCP (Secure Copy Protocol) becomes invaluable.

Audio Briefing
0:00 / 0:00
What Even Is SSH?

SSH allows you to log into a remote computer and run commands securely. Before SSH, tools like Telnet transmitted everything—including passwords—in plain text. SSH fixed this by encrypting the entire session.

Port 22 and Connectivity

By default, SSH connects over port 22. It's a "well-known port" reserved for system services. While you can't hide from determined attackers, moving SSH to a non-standard port (like 2222) dramatically reduces automated brute-force attempts.

To connect to a custom port:

ssh -p 2222 user@yourserver.com
Advertisement

Level Up Your SSH Workflow

Stop Typing Passwords (Use SSH Keys)

Passwords are slow and insecure. Generate an Ed25519 key pair (it's faster and more secure than RSA):

ssh-keygen -t ed25519 -C "your_email@example.com"

Copy the public key to your server. From then on, you log in securely and instantly.

ssh-copy-id user@yourserver.com

Configure Your SSH Profile

Stop memorizing IP addresses and ports. Create an SSH config file (~/.ssh/config) to create clean aliases for your servers.

Host myserver
    HostName 192.168.1.100
    User alice
    Port 2222
    IdentityFile ~/.ssh/id_ed25519

Now, connecting is as simple as typing:

ssh myserver

Transfer Files Securely with SCP

SCP uses SSH under the hood to transfer files between machines. The syntax is simply scp source destination.

Copy to a server:

scp myfile.txt myserver:/home/alice/

Copy from a server (note the trailing ./):

scp myserver:/home/alice/myfile.txt ./
Capital P for SCP Ports

While SSH uses a lowercase -p for custom ports, SCP uses a capital -P. scp -P 2222 myfile.txt user@server:/path/

SCP vs. The Alternatives

SCP is fantastic for quick file transfers, but it isn't always the best tool for the job.

  • rsync: The ultimate tool for syncing directories. It only transfers changed delta blocks, making it drastically faster for large directories. (e.g., rsync -avzP local/ myserver:/remote/)
  • SFTP: A robust subsystem running over SSH that lets you interactively browse, seek, rename, and resume interrupted file transfers.
FeatureSCPrsyncSFTP
Directory Resumption❌ No✅ Yes (--partial)✅ Yes
Delta Compression❌ Whole files✅ Block-level diffs❌ Whole files
Interactive Navigation❌ No❌ No✅ Yes
Standard Availability✅ Everywhere⚠️ Needs rsync on remote✅ Everywhere

SSH Tunneling & Port Forwarding

SSH can tunnel arbitrary TCP traffic through an encrypted pipe, allowing you to access private databases or bypass firewalls safely:

1. Local Port Forwarding (-L)

Forward a port on your local machine to a remote internal database that isn't publicly exposed:

# Connect local localhost:5432 to private RDS instance 10.0.1.25:5432 via bastion
ssh -L 5432:10.0.1.25:5432 user@bastion.example.com

2. Dynamic SOCKS5 Proxy (-D)

Turn your remote server into an instant encrypted browser proxy:

# Start SOCKS5 proxy on local port 1080
ssh -D 1080 -N user@remoteserver.com

Advertisement

Bastion Hosts: SSH ProxyJump

Modern cloud VPCs keep production databases and worker nodes in private subnets with no public IPv4 addresses. Instead of manually SSHing into a bastion and hopping from there, use native ProxyJump (-J):

# ~/.ssh/config configuration for transparent bastion hopping
Host bastion
    HostName bastion.production.internal
    User ec2-user
    IdentityFile ~/.ssh/bastion_key.pem

Host internal-worker-01
    HostName 10.0.2.144
    User ubuntu
    ProxyJump bastion
    IdentityFile ~/.ssh/prod_nodes.pem

Now typing ssh internal-worker-01 automatically routes and authenticates through the bastion seamlessly in a single step!


SSH Permissions & Common Gotchas

SSH enforces strict filesystem permissions to prevent rogue users on multi-tenant machines from reading private keys:

chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_ed25519
chmod 644 ~/.ssh/id_ed25519.pub
chmod 600 ~/.ssh/authorized_keys

Interactive Tool: Need to verify octal and symbolic Linux file permissions? Use our free Linux Chmod Permissions Calculator to quickly calculate exact permissions and umask values.

Crucial Server Hardening Fundamentals

Don't leave your server front door open to brute-force bots! Edit /etc/ssh/sshd_config to harden your configuration:

  1. Disable Password Auth: Set PasswordAuthentication no.
  2. Disable Root Login: Set PermitRootLogin no.
  3. Enforce Modern Ciphers: Restrict key exchange to curve25519-sha256.
  4. Firewall Access: Limit SSH port exposure with ufw allow from <your_ip> to any port 22.
  5. Install Fail2Ban: Automatically ban IP addresses exceeding 3 consecutive failed handshakes.

Frequently Asked Questions

Ed25519 uses twisted Edwards curve cryptography. It generates 68-character compact keys that execute signature handshakes substantially faster than 4096-bit RSA keys, while offering superior resistance to side-channel timing attacks.
This occurs when the server's public key fingerprint changes (common after server re-installations). Verify the remote IP address, then remove the stale host entry using ssh-keygen -R hostname_or_ip.
SCP transfers files in their entirety using standard SSH pipes. rsync calculates rolling checksums across both endpoints to transfer only changed blocks, and supports resuming interrupted transfers and syncing file permissions.

Conclusion

SSH and SCP are the foundational plumbing of cloud systems and DevOps infrastructure. By adopting Ed25519 keys, structuring your ~/.ssh/config profiles, mastering ProxyJump and port forwarding, and hardening sshd_config, you turn fragile remote access into an encrypted, bulletproof workflow.

You Might Also Like

Share this article:

Stay Updated

Get the latest posts delivered straight to your inbox.

Free Developer Utilities

Free In-Browser Developer Tools

Clean AI CLI logs, build cron expressions, decode JWTs, and calculate chmod permissions offline.

Explore Tools
Advertisement