Sprotocols
SCP
The secure-copy command, and historically a simple copy protocol, that moves a file over an SSH channel.
It was built as remote copy: a source path, a destination path, no directory listing, no resume. OpenSSH 9.0, released in 2022, changed the `scp` command to speak SFTP by default. The legacy protocol is still available with `-O`.
The legacy protocol is not an RFC. It rides an SSH exec channel and uses the old remote-copy message style. That design is why OpenSSH moved off it. A malicious server could influence the client more than SFTP allows, and the protocol had no clean extension point. The command name stayed, because scripts call `scp`. The bytes underneath a modern default run are an SFTP transfer. Forcing `-O` restores the old protocol and its risks.
A deploy script runs `scp build.tgz admin@app.example:/var/releases/`. On OpenSSH 9.0 or later, that opens an SFTP subsystem and writes the object. The same script against a server that only allows the legacy protocol fails until someone adds `-O` or enables SFTP. A glob such as `scp logs/*.txt host:` also changes behavior: the legacy protocol expanded the glob on the remote side in some cases, and SFTP expands it locally. A script that copied the wrong set of files after an upgrade is hitting that difference, not a failed SSH login.
SCP the command is not a managed transfer. There is no audit row unless the SSH server logs the session. There is no resume in the legacy protocol. Checksums are the operator's problem before and after the copy. People who say "SCP it" often mean "put it on that host over SSH." Ask whether the remote end must speak the legacy protocol or whether SFTP is enough. For new jobs, SFTP is the protocol. The `scp` binary is a client that may or may not still be using it.
Related
Sources
- OpenSSH 9.0 release notes
scp switched to the SFTP protocol by default; legacy protocol via -O
- RFC 4254, SSH Connection Protocol
The SSH channel both the legacy copy and SFTP run on