How to Connect via SSH

SSH is the technology that lets you securely log into another PC or server over the internet and control it as if it were sitting right in front of you. You'll use it any time you rent a cloud server or want to access your home PC from somewhere else. The protocol sounds complex, but connecting is just one command.

What is SSH?

SSH stands for "Secure Shell." It was introduced in 1995, and today the widely used free implementation is called OpenSSH. Because all traffic is encrypted, anyone who intercepts the connection mid-route can't read its contents. The ssh command is available by default on current major operating systems, including Linux, Mac, and Windows 11.

Usage is simple: type ssh username@server-address. For example, ssh student@example.com attempts to log into example.com as the user "student." Once connected, the terminal in front of you becomes a terminal on that server.

How an SSH connection works

First SSH connection — real terminal example (to a cloud server) One command connects you. The first time only, you're asked whether to trust the remote host. student@laptop:~$ ssh ubuntu@203.0.113.42 ↑ Login request: username@server-IP The authenticity of host '203.0.113.42' can't be established. ECDSA key fingerprint is SHA256:abc123... Are you sure you want to continue connecting (yes/no)? yes ↑ First time only — confirms you trust this server's fingerprint ubuntu@203.0.113.42's password: ●●●●●●●●●● ↑ Enter password (characters are hidden) Welcome to Ubuntu 24.04 LTS ubuntu@cloud-server:~$ _ ↑ Prompt changes to server name = login successful
Fig 1: One ssh command puts a distant server right in your terminal. All traffic is encrypted.

During an SSH connection, both sides verify identity: "Is the server genuine?" and "Are you who you claim to be?" On first connection, you're asked whether to trust this server. Answering yes stores the server's unique ID so future connections can detect if you're redirected to a fake server with a similar address.

Password authentication vs. key authentication

Password auth vs. public-key auth (resistance to attacks) Cloud servers receive thousands of brute-force attempts daily. Key auth is theoretically unbreakable. Method Attempts to crack Convenience 🔑 Password authentication Compares against an 8–12 character password stored on the server 8-char alphanumeric: 60 trillion → Can be cracked in a day in some cases Enter every time Easy but risky 🔐 Public-key authentication (recommended) Cryptographic authentication using a key pair: private key (local) + public key (server) RSA 2048-bit: practically impossible → Hundreds of trillions of years even for supercomputers No password One-time setup Always switch production servers to public-key auth (and disable password auth)
Fig 2: Key auth requires "hundreds of trillions of years" to crack. Always use it on production servers.

SSH supports two authentication methods: password-based and key pair-based. With key pairs, you keep a "private key" on your local machine and place a "public key" on the server. Neither is useful without the other. Because this defeats brute-force attacks, key auth is standard on any publicly accessible server.

Creating a key pair takes one command: ssh-keygen. Copy the contents of the generated ~/.ssh/id_rsa.pub (your public key) into the server's ~/.ssh/authorized_keys, and you'll log in without a password from then on.

Recommended usage

Renting a server on a cloud free tier or low-cost plan and connecting via SSH is one of the best ways to get real-world experience. Check the official pricing and set up billing alerts before you start — free tier conditions change. A Raspberry Pi connected to your home Wi-Fi makes a great SSH practice target too.

VS Code (free editor) has a "Remote - SSH" extension that lets you edit files on a server directly in your local editor. It's an ideal tool who want to feel what remote development is like.

For practice, start by SSHing from your own PC into a Raspberry Pi or a virtual machine. Once connected, run whoami, pwd, and ls to confirm you're operating on the remote side, not your local machine. Keeping this distinction clear prevents accidental edits in the wrong place.

Traps to watch out for

SSH safety reminders
  • Never share or expose your private key (id_rsa). If it leaks, your server can be taken over.
  • A password-authenticated server on port 22 receives thousands of attack attempts per day. Switch to key auth as soon as possible.
  • Commands you run after SSH login act directly on the server's files. Files deleted with rm cannot be recovered.

How will this help you in the future?

SSH is a daily tool for web engineers, infrastructure engineers, and data scientists alike. Deploying to cloud servers, running machine-learning training jobs, remote development — all of it goes through SSH. Being comfortable with key authentication by the time you're in high school makes you a "ready-to-contribute" candidate when you start working or interning.

Learning SSH also builds the instinct for safely controlling computers over a network. This skill carries over to cloud platforms, university computing clusters, and remote development setups. Develop good habits along the way: never hand out your private key, verify the server you're connecting to, and shut down servers you no longer need.

Start today

3 steps to get started
  1. Run ssh-keygen in your terminal to create an SSH key pair (set a passphrase for extra security).
  2. Sign up for a cloud free-tier server (AWS Lightsail, Oracle Cloud Free Tier, etc.) with a parent or guardian.
  3. Register your public key on the server and try connecting with ssh username@IP.

Summary

SSH is a system for safely logging into and controlling a remote server over the internet. The command is ssh username@address — just one line — and all traffic is encrypted, so even if intercepted it can't be read. Always switch to public-key authentication on production servers, and never show your private key to anyone. Practice with a cloud server or Raspberry Pi and you'll quickly feel what real-world IT work is like.

Check SSH's job is?