SSH and SCP: The Two Tools Every Developer Should Actually Understand

Table of Contents(11 sections)
If you've spent any time working with servers, you've likely typed ssh into a terminal without thinking too hard about it. But when you get locked out at 2 AM or file transfers keep failing, knowing the mechanics of SSH (Secure Shell) and SCP (Secure Copy Protocol) becomes invaluable.
What Even Is SSH?
SSH allows you to log into a remote computer and run commands securely. Before SSH, tools like Telnet transmitted everything—including passwords—in plain text. SSH fixed this by encrypting the entire session.
Port 22 and Connectivity
By default, SSH connects over port 22. It's a "well-known port" reserved for system services. While you can't hide from determined attackers, moving SSH to a non-standard port (like 2222) dramatically reduces automated brute-force attempts.
To connect to a custom port:
ssh -p 2222 user@yourserver.com
Level Up Your SSH Workflow
Stop Typing Passwords (Use SSH Keys)
Passwords are slow and insecure. Generate an Ed25519 key pair (it's faster and more secure than RSA):
ssh-keygen -t ed25519 -C "your_email@example.com"
Copy the public key to your server. From then on, you log in securely and instantly.
ssh-copy-id user@yourserver.com
Configure Your SSH Profile
Stop memorizing IP addresses and ports. Create an SSH config file (~/.ssh/config) to create clean aliases for your servers.
Host myserver
HostName 192.168.1.100
User alice
Port 2222
IdentityFile ~/.ssh/id_ed25519
Now, connecting is as simple as typing:
ssh myserver
Transfer Files Securely with SCP
SCP uses SSH under the hood to transfer files between machines. The syntax is simply scp source destination.
Copy to a server:
scp myfile.txt myserver:/home/alice/
Copy from a server (note the trailing ./):
scp myserver:/home/alice/myfile.txt ./
Capital P for SCP Ports
While SSH uses a lowercase -p for custom ports, SCP uses a capital -P.
scp -P 2222 myfile.txt user@server:/path/
SCP vs. The Alternatives
SCP is fantastic for quick file transfers, but it isn't always the best tool for the job.
rsync: The ultimate tool for syncing directories. It only transfers changed delta blocks, making it drastically faster for large directories. (e.g.,rsync -avzP local/ myserver:/remote/)- SFTP: A robust subsystem running over SSH that lets you interactively browse, seek, rename, and resume interrupted file transfers.
| Feature | SCP | rsync | SFTP |
|---|---|---|---|
| Directory Resumption | ❌ No | ✅ Yes (--partial) | ✅ Yes |
| Delta Compression | ❌ Whole files | ✅ Block-level diffs | ❌ Whole files |
| Interactive Navigation | ❌ No | ❌ No | ✅ Yes |
| Standard Availability | ✅ Everywhere | ⚠️ Needs rsync on remote | ✅ Everywhere |
SSH Tunneling & Port Forwarding
SSH can tunnel arbitrary TCP traffic through an encrypted pipe, allowing you to access private databases or bypass firewalls safely:
1. Local Port Forwarding (-L)
Forward a port on your local machine to a remote internal database that isn't publicly exposed:
# Connect local localhost:5432 to private RDS instance 10.0.1.25:5432 via bastion
ssh -L 5432:10.0.1.25:5432 user@bastion.example.com
2. Dynamic SOCKS5 Proxy (-D)
Turn your remote server into an instant encrypted browser proxy:
# Start SOCKS5 proxy on local port 1080
ssh -D 1080 -N user@remoteserver.com
Bastion Hosts: SSH ProxyJump
Modern cloud VPCs keep production databases and worker nodes in private subnets with no public IPv4 addresses. Instead of manually SSHing into a bastion and hopping from there, use native ProxyJump (-J):
# ~/.ssh/config configuration for transparent bastion hopping
Host bastion
HostName bastion.production.internal
User ec2-user
IdentityFile ~/.ssh/bastion_key.pem
Host internal-worker-01
HostName 10.0.2.144
User ubuntu
ProxyJump bastion
IdentityFile ~/.ssh/prod_nodes.pem
Now typing ssh internal-worker-01 automatically routes and authenticates through the bastion seamlessly in a single step!
SSH Permissions & Common Gotchas
SSH enforces strict filesystem permissions to prevent rogue users on multi-tenant machines from reading private keys:
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_ed25519
chmod 644 ~/.ssh/id_ed25519.pub
chmod 600 ~/.ssh/authorized_keys
Interactive Tool: Need to verify octal and symbolic Linux file permissions? Use our free Linux Chmod Permissions Calculator to quickly calculate exact permissions and umask values.
Crucial Server Hardening Fundamentals
Don't leave your server front door open to brute-force bots! Edit /etc/ssh/sshd_config to harden your configuration:
- Disable Password Auth: Set
PasswordAuthentication no. - Disable Root Login: Set
PermitRootLogin no. - Enforce Modern Ciphers: Restrict key exchange to
curve25519-sha256. - Firewall Access: Limit SSH port exposure with
ufw allow from <your_ip> to any port 22. - Install Fail2Ban: Automatically ban IP addresses exceeding 3 consecutive failed handshakes.
Frequently Asked Questions
ssh-keygen -R hostname_or_ip.Conclusion
SSH and SCP are the foundational plumbing of cloud systems and DevOps infrastructure. By adopting Ed25519 keys, structuring your ~/.ssh/config profiles, mastering ProxyJump and port forwarding, and hardening sshd_config, you turn fragile remote access into an encrypted, bulletproof workflow.
You Might Also Like
Free In-Browser Developer Tools
Clean AI CLI logs, build cron expressions, decode JWTs, and calculate chmod permissions offline.
Related Articles

Cilium vs Calico with eBPF: Kubernetes Network Throughput, Security & Service Mesh
Comprehensive guide covering cilium vs calico with ebpf: kubernetes network throughput, security & service mesh with production-grade architecture and code examples.
Read more
Implementing Zero-Trust Security in Kubernetes: The Complete Production Guide
Practical guide to eliminating flat-network perimeter security in Kubernetes: default-deny NetworkPolicies, SPIFFE/SPIRE workload identity, and strict mTLS.
Read more
GitHub Actions Self-Hosted Runner Security Hardening
Harden self-hosted GitHub Actions runners using Actions Runner Controller (ARC), network isolation, rootless containers, and short-lived OIDC tokens.
Read more