3 ms·
Has anyone else ran into cheap hosting providers where scp would work but sftp doesn't? I hope this change will make them reconsider their configuration.
by pdenton 5y ago
Has anyone else ran into cheap hosting providers where scp would work but sftp doesn't? I hope this change will make them reconsider their configuration.
- encryptluks2 5y agoIf SCP works but SFTP doesn't, then they are most likely running an outdated version of OpenSSH with insecure algorithms.
- hackerbrother 5y agoOpenSSH's habit of giving their tools the same name as protocols makes this confusing to talk about. SCP (the tool) uses SFTP (the protocol) by default, right?
- formerly_proven 5y agoscp uses a custom stream protocol over stdout/stdin. It's more like a tarpipe, though shares nothing in terms of format with that. SFTP is essentially RPC for the various I/O syscalls (open, read, write, ...) - it's basically NFS-as-a-user over SSH. Read/write size is limited to 32 kB per request (in OpenSSH / minimum supported size).
- acdha 5y agoscp the tool uses the SCP protocol by default. Recent versions allow you to use sftp instead: -s Use the SFTP protocol for transfers rather than the original scp protocol.
- hackerbrother 5y agoAh, now I know why I was confused. It hasn't happened yet, but sftp will be the default protocol soon. > A near-future release of OpenSSH will switch scp(1) from using the legacy scp/rcp protocol to using SFTP by default. https://www.openssh.com/releasenotes.html https://www.openssh.com/releasenotes.html
- adrian_b 5y agoNo, many administrators, like myself, disable the SFTP protocol, even if they always use the up-to-date OpenSSH. I also always remove scp because I use only rsync over ssh, which does not have the inherent bugs of scp and sftp and is also much faster.
- chasil 5y agoSFTP requires the subsystem to be enabled, and can be implemented either by an external binary or an internal OpenSSH implementation (some SSH servers do not implement it internally). SCP is always external, and merely needs to be found in the path. Because it's much more simple to configure, greater ubiquity is not surprising.
- throwawayboise 5y agoscp is effectively: cat foo | ssh user@remote 'cat > foo' That is why all the escaping is necessary.