MagiskSSH – SSH server on Android without Termux
gitlab.com
gitlab.com
After years of trying to keep up with Google's perpetual Android tweaks, I gave up and accepted that they would eventually remove any apps that weren't updated for each new Android version.
These events only remind me how out-of-date I am as a programmer. I wrote and released my first major title, Apple Writer (https://en.wikipedia.org/wiki/Apple_Writer) in 1979. It lasted for six years in various forms, then was replaced by better programs. I wasn't a corporation, I was an individual, and my programs (then and since) have been individual projects.
In modern times, individual releases are rare, and in the future are likely to be even more rare, replaced by collaborations between developer teams and AI.
Not saying things were better in the past. Just different.
The user is now viewed as a security threat to their own device, the hyper-churn culture of the javascript ecosystem is now embedding in other areas even systems (like Android, as you point out), "updates" for apps and to a lesser but growing extent OSes, are routinely pushed and forced on users regardless whether they contain new bugs/regressions or horrible UI/UX changes, more and more software is becoming proprietary SaaS and "subscription" based, and backwards compatibility is for the birds. In the name of "security", tech companies and even individual devs are turning our own home networks into opaque spy apparatuses that make network connections that we (the owners of the network) can't even inspect. Even maintaining self-hosted apps is becoming a several-hours-per-week job.
It feels like during the late 00s and early 10s we had some real golden years of open source, but now the poisonous engineering culture that pushes the above things is poised to squash it as a "daily driver" for people. For example, once Microsoft completes their requirements for TPMS and can do hardware attestation like Apple and Google, the ratchet of websites not working (or not working completely) unless the device passes hardware attestation will start, and it will make life on a Linux laptop/desktop similar to how Tor is now where you get endless CAPTCHA hell and nobody cares because you're in a tiny minority of users and many of the tools that provide technological liberation for an individual are also tools used by gray and black hat actors.
And I haven't even gotten to the Apple-ization of everything where it's becoming all about building walled gardens. I remember when compatibility was a selling point of hardware/software.
It's not all bad of course, but it does feel like a lot more bad than good is developing. Happy Monday everyone!
I do understand trying to bury full access to the device a bit deeper than it was on older PC operating systems. The average person doesn't know how to use a computer, and it doesn't appear there was ever much hope of that situation changing. Letting a third party verify the computer is in a certain state, however seems outright malicious.
I'm SSHing regularly into my Android phone (and it does not need root) for backup purposes. Used various apps for that but settled for years on Termux.
* Install https://f-droid.org/ store
* Install Termux from there
* Install ssh daemon and rsync in Termux with
pkg upgrade
pkg install openssh rsync
* Read manual on https://wiki.termux.com/wiki/Remote_Access#Using_the_SSH_ser... on how to start, configure, stop ssh daemon. In general: The Termux documentation is good!Not arguing, just curious.
And also: I don't want to connect my phone over the cable to my PC very often. I just want to quickly transfer sometimes (over WiFi).
- Always available over my network/wireguard without touching the phone or a cable. Wireless ADB over a tcp socket technically works but requires a USB cable to bootstrap when you use the phone as a hotspot like I do, nor would I dare open it up to the internet.
- Any number of SFTP clients rather than the limited ADB options
- Higher throughput than wired ADB (at least on my Pixel 6A over USB)
- I want ssh access to my termux environment anyway so may as well use it for file transfers too.
I only really use adb for app development, maybe the odd nslookup or android package management with `pm`
Also this lets you run script on your real device instead of the chroot thing of termux which can be helpful (e.g. accessing /data/data stuff which is a pain with termux, not sure if its even possible).
And my last reason is just that why would I need a separate app that I need to configure when I can just have a real ssh server
I would take rsync any day over unreliable GUI apps that silently fail to complete remote transfers, often as soon as the screen is turned off.
I've used an iPhone for the past few years but may move to a Pixel running GrapheneOS for my next phone. It's apps (well, modules) like this and Termux that tip the scales in Android's favor.
If your phone's manufacturer disabled the necessary power saving settings, I doubt they'll enable them for the Android 15 terminal.
To be fair, for every well behaved background app (ie. a ssh server that's listening on a socket, which should consume basically zero power), there's probably 10 other misbehaving app that's phoning home every 30 seconds for ad/tracking/analytics purposes. Moreover, "battery life" is a metric that often shows up on reviews, so it makes sense to game this metric as hard as possible, especially since most people probably aren't running servers 24/7 on their phones.
I run into issues with the smart watch integration app getting killed before Google Maps, even when I'm not navigating on one of my devices. No way to whitelist the integration app or set some kind of preference, it's just a lottery, probably based on guesstimated power consumption (which, for an app with a Bluetooth lock, will probably be above average) that I want to tweak.
When these are the tasks that are killed, it costs me more than whatever precious bodily fluids that some ad/tracking/analytics stuff may sap: It costs me real money.
Dollars I have lost due to things phoning home against my expectations: Close to zero -- if not literally zero. (And close to zero time spent managing that.)
Dollars I have lost due to things failing to phone home when I want them to do so: More than zero. (And hours and hours of time spent trying to make them work more reliably.)
None of this invalidates your use case, but given the rarity of your use case compared to the more common use case, I hope you understand why companies are implementing it not purely out of "spite".
A thing can be abhorrent and disdainful and motivated by the best and most pure of intentions, all at the same time. These are not in any way mutually-exclusive constructs.
Rarity?
Perhaps the best way to make sure a thing remains rare or unusual is to neuter it straight out of the gate. In the past few days here we've seen SSH servers and Docker containers on Android, with the repeated caveat of "Yeah, but the task killer won't let that really work." And that's absolutely true: It won't.
Don't forget all the crap they can run in the freed capacity now!
It's less hardened than Graphene, but more user-friendly (IMHO) and similarly avoids Google spyware.
The Bliss launcher leaves a number of features to be desired. I can't see how to create a shortcut of the browser as an incognito tab, which for me is a must-have. The lack of widgets beyond the separate widget pane also is limiting.
I've seen some methods to get Trebuchet imported by various means. That would be required for a daily driver.
Otherwise it looks like a reasonable clone of Lineage with odds and ends.
Edit: LineageOS bundles /product/bin/sshd - I have seen wikis on how to set this up with authorized_keys. /e/OS likely has the server daemon as well. My phone says that it's OpenSSH 9.0p1, BoringSSL.
So does google maps.
GrapheneOS and /e/OS are trying to solve different problems: producing a usable Android operating system that isn't tied to Google.
For some reason I can swipe it away too, while from what I remember, persisting apps like this used to prevent you from doing so
Honestly Graphene is the first where everything just worked, and gave me the option to take or leave google apps, and have them in a sandbox if I desired.
Probably the first time I haven't felt the need to root or install magisk modules to customize behavior.
For me it's like having your cake and eating it too.
To be honest, and this probably seems minor / trivial, but one of the only things I miss about using GOS is the ability to turn on the flash light by holding the power or whatever other button.
I'm curious about the rough edges you experienced.
1. apps are rather slow to install, since GOS compiles JIT (just-in-time compiled code) on install for security/speed. It's a bit of a pain when I'm needing something now 2. play integrity fails, so some banks¹ don't work, and NFC payments are pretty much bricked 3. I had some weird issue setting up my galaxy watch. probably a Samsung thing but it'd download software for an hour then fail with a generic message multiple times
now writing this out, I realize a lot of these are skill issues I need to just take a couple hours and try to fix
1: my solution is just to use web apps and it works well since I end up with less apps. PWA FTW!
If you only care about running open source code, you're golden.
https://play.google.com/store/apps/details?id=com.theolivetr...
> This app isn't available for your device because it was made for an older version of Android.
Nevertheless, an alternative is Material Files, a FOSS file manager that includes an FTP Server and Client:
* https://f-droid.org/packages/me.zhanghai.android.files
* https://play.google.com/store/apps/details?id=me.zhanghai.an...
Though I'm pretty sure you can just flash magisk / magisk modules as you would with any other ROM.
I used to spend lots of time trying different ROMs, figuring out SU and SELinux stuff, and fighting with SafetyNet. These days I just use stock Samsung ROM. I still have Termux on my devices but only use them occasionally when I don't have a laptop next to me and need to do some hardcore stuff. (I might even switch to iPhone someday because the password autofill experience on Android is just atrocious and infuriating while Google has done almost nothing for the past few years.)
You will still fail to pass device verification, but that doesn't really matter to me. I don't use tap to pay (that's why NFC credit cards are for) nor play any mobile games that actually care.
I could not imagine using a stock Samsung ROM personally, but to be fair, it has been years since I tried. Maybe I'm still just too burned from the bloatware of the early Galaxy days.
e.g. if I open doordash and try to log in, which opens a web view with a login form, does autofill popup?
In my experience, autofill works the best in Chrome if you have all your entire digital life dedicated to Google's ecosystem.
But I use Firefox with Bitwarden, which works at most 50% of the time. That works about 85% of the time on iPhone or iPad.
> e.g. if I open doordash and try to log in, which opens a web view with a login form, does autofill popup?
yes, I just checked with Gmail > random website in Gmail WebView, and Firefox autofilled it fine. That being said, WebView's can be unique app to app, so can't promise it works for door dash as I don't have that app.
What do you mean?
That means you can’t use something like pihole with android.
1. https://www.reddit.com/r/pihole/comments/18ov638/pi_hole_on_...
When you install pihole and set it as the dhcp server and also as the IPv6 „Ra“ server the ipv6 dns server from your router will still be used primarily. Making dns based blocking on android ineffective
Can I mount remote filesystems at the system level via sshfs?
This module isn't affected by battery-saving mechanisms because it runs as a system process rather than an app process.
Termux is rock solid on my Galaxy Fold 4 without any root or adb shenanigans.
Edit: .. though, one could always just start an ssh server in Termux in the OS for this.
Maybe it's if you want to have ssh and rsync in the recovery or fastboot modes? Just in case you can't get (or don't want) to run the android system?
Edit2: Ah. It's for when you want to use another app that can call system commands, without having to build ssh and rsync into the app, nor spawn an intermediate termux process from the app. It cuts out the middle-man. That is quite useful.
If so it would be very useful for use with rclone. I back up my phone by running an sshd in termux then using rclone with sftp remotely. This works very well (until the phone decides on a whim to kill the sshd!).
In f-droid, there is also a "primitive FTP server" that includes an SFTP, but that probably gets killed unless you are very careful.
start rsync daemon: adb root adb forward tcp:6010 tcp:11873 adb shell "rsync --daemon --port 11873 --config=/sdcard/rsyncd.conf &"
rsync: rsync -rltHDhP --stats --size-only --append-verify --partial --delete rsync://localhost:6010/root/data/data/ /backup/data
cleanup: adb kill-server
/sdcard/rsyncd.conf for the phone: address = 127.0.0.1 uid = root gid = root [root] path = / read only = true