This is useful when the local network is untrusted, or to bypass things like url blocklists or IP filtering.
The arguments are as follows:
ssh -C2qTnN -D 8080 your-user@example.com
C2: request compression, at level 2 (1 is least)
q: quite mode
T: Disable pseudo-tty allocation. I don't know why you would want this. I suspect since you are only using it for a proxy you don't really need a tty, but seems a little unnecessary to me.
n: redirect stdin from /dev/null. Again, not sure why this is needed, but I suspect it is related to the "T" option.
N: Do not execute a remote command. You are only using port forwarding so no commands are needed.
-D 8080: the local port to forward
your-user@example.com: Username/host of remote machine.
This is a pretty optimized example. The simplest working version is just ssh -D 8080 your-user@example.com. Personally, I'd use the -C2 argument as well, but leave the rest out.
Similarly, -n is described as necessary for backgrounding the process, if you want to. I can't find a reason to use -T, unless you intend to send binary data over the pipe.
A typical use for this is when you are connected to a foreign network like a hotel. If you don't route your http traffic over ssh, there is a risk of having your traffic sniffed and/or recorded.
- watch Hulu, when you're not in the US
- use Spotify when you are in the US (and you use a UK box for example)
- bypass your university firewall
- in general secure your connection in case you are using an open network