Repository files navigation

SSHShift

Shift from Windows key → PuTTY → Enter → host → Enter to Debian's OpenSSH—without a hard landing.

SSHShift is a profile-free KDE launcher for OpenSSH, built for Windows administrators moving their daily work to Debian. It provides a familiar “enter a host and connect” window, then gets out of the way and lets the system's real ssh client run inside Konsole.

The Shift suite

ToolFamiliar starting pointDebian engine
RDPShiftAn mstsc-style “enter a computer and connect” workflowFreeRDP
SSHShiftWindows key → PuTTY → Enter → host → Enter, made native to KDEOpenSSH + Konsole
MapShiftA familiar “map network drive” path into KDE applicationsKDE KIO SMB + KIO-FUSE
ServiceShiftA services.msc-style overview with familiar service controlssystemd + PolicyKit
TaskShiftA Task Scheduler-style overview with safe schedule editingsystemd timers + PolicyKit

SSHShift supports Debian 13 with KDE Plasma and Wayland.

Why it exists

Debian already ships excellent administration tools, but a command prompt can be an unnecessarily abrupt first step for administrators arriving from Windows. SSHShift provides a softer landing without replacing OpenSSH, inventing a new protocol stack, or locking users into its interface.

The Advanced options panel shows the equivalent ssh command for the current choices. The launcher can therefore act as training wheels: use the graphical workflow today and take the same command to a terminal whenever you are ready.

Updates stay with Debian

SSHShift does not bundle its own SSH implementation. It launches the OpenSSH and Konsole packages maintained by Debian, so normal apt upgrades deliver their security and bug fixes through the same trusted update path as the rest of the system. There is no separate full client, private protocol copy, or extra updater that can quietly fall behind.

The small wrapper may occasionally need a compatibility or interface update, but the security-sensitive SSH engine remains Debian's package—not frozen inside SSHShift.

Behavior and privacy

  • No connection profiles, recent-host list, saved usernames, or saved passwords.
  • Destination and optional jump-host details have separate cards on the main screen, each pairing its Host and Username fields clearly. Host fields also accept [username@]hostname[:port] notation.
  • Authentication is performed directly by OpenSSH in Konsole. SSHShift never asks for or handles the password.
  • The hostname, username, jump host, and options are supplied through a private OpenSSH configuration under /run/user/$UID, not command-line arguments.
  • The private runtime directory is removed when the Konsole session ends.
  • Persistent host-key lookup uses a keyed HMAC of the normalized hostname and port as an opaque identity.
  • The random HMAC key is held in KDE Wallet.
  • The real hostname exists in a private known-hosts file under /run/user/$UID only while the session is active, so OpenSSH's prompts remain readable.
  • When the session ends, SSHShift translates the transient hostname back to its opaque identity before updating persistent trust.
  • OpenSSH asks before trusting a host for the first time, silently accepts an unchanged key, and refuses a changed key.
  • SSH agent and X11 forwarding are off by default and reset after each launch.
  • An explicitly selected identity file and jump host apply only to the current connection.

The persistent known-host database is stored at $XDG_DATA_HOME/ssh-shift/known_hosts, normally ~/.local/share/ssh-shift/known_hosts. It contains public host keys indexed by KDE-Wallet-keyed opaque aliases—not server names.

Installation on Debian 13

Install the runtime dependencies:

sudo apt install openssh-client konsole python3-dbus python3-pyqt6

Then install SSHShift for the current user:

./install.sh

The application appears as SSHShift in Plasma's application menu. The installer defaults to ~/.local; set PREFIX to choose another user prefix.

To uninstall the launcher:

./uninstall.sh

Uninstalling deliberately preserves the known-host database and KDE Wallet key so reinstalling does not silently discard host-key-change protection.

Connection options

  • Identity file: selects one private key for this connection. When empty, OpenSSH uses its normal default keys and SSH agent.
  • Jump host: routes through a bastion using OpenSSH ProxyJump; it is on the main screen because bastions are part of many administrators' daily workflow. A separate Jump username field is provided, while username@host notation remains supported. Its identity is protected in the same known-host database.
  • Agent forwarding: off by default because a privileged user on the remote host could use the forwarded agent while the connection is active.
  • X11 forwarding: off by default; when enabled, SSHShift requests OpenSSH's untrusted X11 mode.
  • Equivalent command: shows the ordinary OpenSSH command represented by the selected options in the Advanced panel.

If Konsole needs time to start, SSHShift displays a cancellable progress window instead of appearing unresponsive.

Testing

python3 -m unittest discover -s tests -v
python3 -m py_compile ssh-shift

The tests cover endpoint validation, configuration-injection defenses, native UI defaults, command previews, HMAC host aliases, private file permissions, OpenSSH configuration parsing, and destination-free launcher arguments.

Threat-model boundaries

SSHShift prevents this launcher and OpenSSH's user known-host file from retaining recoverable destination names. It cannot hide a live connection from DNS, network equipment, the destination, the operating system, or an attacker able to inspect process memory or an unlocked KDE Wallet. See SECURITY.md for details.

OpenSSH remains responsible for SSH cryptography, authentication, protocol compatibility, host-key validation, and the remote session.

License

MIT. See LICENSE.

About

A privacy-conscious, profile-free KDE launcher for Debian's OpenSSH—a softer landing for Windows admins moving to Linux.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

SSHShift

Shift from Windows key → PuTTY → Enter → host → Enter to Debian's OpenSSH—without a hard landing.

SSHShift is a profile-free KDE launcher for OpenSSH, built for Windows administrators moving their daily work to Debian. It provides a familiar “enter a host and connect” window, then gets out of the way and lets the system's real ssh client run inside Konsole.

The Shift suite

ToolFamiliar starting pointDebian engine
RDPShiftAn mstsc-style “enter a computer and connect” workflowFreeRDP
SSHShiftWindows key → PuTTY → Enter → host → Enter, made native to KDEOpenSSH + Konsole
MapShiftA familiar “map network drive” path into KDE applicationsKDE KIO SMB + KIO-FUSE
ServiceShiftA services.msc-style overview with familiar service controlssystemd + PolicyKit
TaskShiftA Task Scheduler-style overview with safe schedule editingsystemd timers + PolicyKit

SSHShift supports Debian 13 with KDE Plasma and Wayland.

Why it exists

Debian already ships excellent administration tools, but a command prompt can be an unnecessarily abrupt first step for administrators arriving from Windows. SSHShift provides a softer landing without replacing OpenSSH, inventing a new protocol stack, or locking users into its interface.

The Advanced options panel shows the equivalent ssh command for the current choices. The launcher can therefore act as training wheels: use the graphical workflow today and take the same command to a terminal whenever you are ready.

Updates stay with Debian

SSHShift does not bundle its own SSH implementation. It launches the OpenSSH and Konsole packages maintained by Debian, so normal apt upgrades deliver their security and bug fixes through the same trusted update path as the rest of the system. There is no separate full client, private protocol copy, or extra updater that can quietly fall behind.

The small wrapper may occasionally need a compatibility or interface update, but the security-sensitive SSH engine remains Debian's package—not frozen inside SSHShift.

Behavior and privacy

  • No connection profiles, recent-host list, saved usernames, or saved passwords.
  • Destination and optional jump-host details have separate cards on the main screen, each pairing its Host and Username fields clearly. Host fields also accept [username@]hostname[:port] notation.
  • Authentication is performed directly by OpenSSH in Konsole. SSHShift never asks for or handles the password.
  • The hostname, username, jump host, and options are supplied through a private OpenSSH configuration under /run/user/$UID, not command-line arguments.
  • The private runtime directory is removed when the Konsole session ends.
  • Persistent host-key lookup uses a keyed HMAC of the normalized hostname and port as an opaque identity.
  • The random HMAC key is held in KDE Wallet.
  • The real hostname exists in a private known-hosts file under /run/user/$UID only while the session is active, so OpenSSH's prompts remain readable.
  • When the session ends, SSHShift translates the transient hostname back to its opaque identity before updating persistent trust.
  • OpenSSH asks before trusting a host for the first time, silently accepts an unchanged key, and refuses a changed key.
  • SSH agent and X11 forwarding are off by default and reset after each launch.
  • An explicitly selected identity file and jump host apply only to the current connection.

The persistent known-host database is stored at $XDG_DATA_HOME/ssh-shift/known_hosts, normally ~/.local/share/ssh-shift/known_hosts. It contains public host keys indexed by KDE-Wallet-keyed opaque aliases—not server names.

Installation on Debian 13

Install the runtime dependencies:

sudo apt install openssh-client konsole python3-dbus python3-pyqt6

Then install SSHShift for the current user:

./install.sh

The application appears as SSHShift in Plasma's application menu. The installer defaults to ~/.local; set PREFIX to choose another user prefix.

To uninstall the launcher:

./uninstall.sh

Uninstalling deliberately preserves the known-host database and KDE Wallet key so reinstalling does not silently discard host-key-change protection.

Connection options

  • Identity file: selects one private key for this connection. When empty, OpenSSH uses its normal default keys and SSH agent.
  • Jump host: routes through a bastion using OpenSSH ProxyJump; it is on the main screen because bastions are part of many administrators' daily workflow. A separate Jump username field is provided, while username@host notation remains supported. Its identity is protected in the same known-host database.
  • Agent forwarding: off by default because a privileged user on the remote host could use the forwarded agent while the connection is active.
  • X11 forwarding: off by default; when enabled, SSHShift requests OpenSSH's untrusted X11 mode.
  • Equivalent command: shows the ordinary OpenSSH command represented by the selected options in the Advanced panel.

If Konsole needs time to start, SSHShift displays a cancellable progress window instead of appearing unresponsive.

Testing

python3 -m unittest discover -s tests -v
python3 -m py_compile ssh-shift

The tests cover endpoint validation, configuration-injection defenses, native UI defaults, command previews, HMAC host aliases, private file permissions, OpenSSH configuration parsing, and destination-free launcher arguments.

Threat-model boundaries

SSHShift prevents this launcher and OpenSSH's user known-host file from retaining recoverable destination names. It cannot hide a live connection from DNS, network equipment, the destination, the operating system, or an attacker able to inspect process memory or an unlocked KDE Wallet. See SECURITY.md for details.

OpenSSH remains responsible for SSH cryptography, authentication, protocol compatibility, host-key validation, and the remote session.

License

MIT. See LICENSE.

About

A privacy-conscious, profile-free KDE launcher for Debian's OpenSSH—a softer landing for Windows admins moving to Linux.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

SSHShift

Shift from Windows key → PuTTY → Enter → host → Enter to Debian's OpenSSH—without a hard landing.

SSHShift is a profile-free KDE launcher for OpenSSH, built for Windows administrators moving their daily work to Debian. It provides a familiar “enter a host and connect” window, then gets out of the way and lets the system's real ssh client run inside Konsole.

The Shift suite

ToolFamiliar starting pointDebian engine
RDPShiftAn mstsc-style “enter a computer and connect” workflowFreeRDP
SSHShiftWindows key → PuTTY → Enter → host → Enter, made native to KDEOpenSSH + Konsole
MapShiftA familiar “map network drive” path into KDE applicationsKDE KIO SMB + KIO-FUSE
ServiceShiftA services.msc-style overview with familiar service controlssystemd + PolicyKit
TaskShiftA Task Scheduler-style overview with safe schedule editingsystemd timers + PolicyKit

SSHShift supports Debian 13 with KDE Plasma and Wayland.

Why it exists

Debian already ships excellent administration tools, but a command prompt can be an unnecessarily abrupt first step for administrators arriving from Windows. SSHShift provides a softer landing without replacing OpenSSH, inventing a new protocol stack, or locking users into its interface.

The Advanced options panel shows the equivalent ssh command for the current choices. The launcher can therefore act as training wheels: use the graphical workflow today and take the same command to a terminal whenever you are ready.

Updates stay with Debian

SSHShift does not bundle its own SSH implementation. It launches the OpenSSH and Konsole packages maintained by Debian, so normal apt upgrades deliver their security and bug fixes through the same trusted update path as the rest of the system. There is no separate full client, private protocol copy, or extra updater that can quietly fall behind.

The small wrapper may occasionally need a compatibility or interface update, but the security-sensitive SSH engine remains Debian's package—not frozen inside SSHShift.

Behavior and privacy

  • No connection profiles, recent-host list, saved usernames, or saved passwords.
  • Destination and optional jump-host details have separate cards on the main screen, each pairing its Host and Username fields clearly. Host fields also accept [username@]hostname[:port] notation.
  • Authentication is performed directly by OpenSSH in Konsole. SSHShift never asks for or handles the password.
  • The hostname, username, jump host, and options are supplied through a private OpenSSH configuration under /run/user/$UID, not command-line arguments.
  • The private runtime directory is removed when the Konsole session ends.
  • Persistent host-key lookup uses a keyed HMAC of the normalized hostname and port as an opaque identity.
  • The random HMAC key is held in KDE Wallet.
  • The real hostname exists in a private known-hosts file under /run/user/$UID only while the session is active, so OpenSSH's prompts remain readable.
  • When the session ends, SSHShift translates the transient hostname back to its opaque identity before updating persistent trust.
  • OpenSSH asks before trusting a host for the first time, silently accepts an unchanged key, and refuses a changed key.
  • SSH agent and X11 forwarding are off by default and reset after each launch.
  • An explicitly selected identity file and jump host apply only to the current connection.

The persistent known-host database is stored at $XDG_DATA_HOME/ssh-shift/known_hosts, normally ~/.local/share/ssh-shift/known_hosts. It contains public host keys indexed by KDE-Wallet-keyed opaque aliases—not server names.

Installation on Debian 13

Install the runtime dependencies:

sudo apt install openssh-client konsole python3-dbus python3-pyqt6

Then install SSHShift for the current user:

./install.sh

The application appears as SSHShift in Plasma's application menu. The installer defaults to ~/.local; set PREFIX to choose another user prefix.

To uninstall the launcher:

./uninstall.sh

Uninstalling deliberately preserves the known-host database and KDE Wallet key so reinstalling does not silently discard host-key-change protection.

Connection options

  • Identity file: selects one private key for this connection. When empty, OpenSSH uses its normal default keys and SSH agent.
  • Jump host: routes through a bastion using OpenSSH ProxyJump; it is on the main screen because bastions are part of many administrators' daily workflow. A separate Jump username field is provided, while username@host notation remains supported. Its identity is protected in the same known-host database.
  • Agent forwarding: off by default because a privileged user on the remote host could use the forwarded agent while the connection is active.
  • X11 forwarding: off by default; when enabled, SSHShift requests OpenSSH's untrusted X11 mode.
  • Equivalent command: shows the ordinary OpenSSH command represented by the selected options in the Advanced panel.

If Konsole needs time to start, SSHShift displays a cancellable progress window instead of appearing unresponsive.

Testing

python3 -m unittest discover -s tests -v
python3 -m py_compile ssh-shift

The tests cover endpoint validation, configuration-injection defenses, native UI defaults, command previews, HMAC host aliases, private file permissions, OpenSSH configuration parsing, and destination-free launcher arguments.

Threat-model boundaries

SSHShift prevents this launcher and OpenSSH's user known-host file from retaining recoverable destination names. It cannot hide a live connection from DNS, network equipment, the destination, the operating system, or an attacker able to inspect process memory or an unlocked KDE Wallet. See SECURITY.md for details.

OpenSSH remains responsible for SSH cryptography, authentication, protocol compatibility, host-key validation, and the remote session.

License

MIT. See LICENSE.

About

A privacy-conscious, profile-free KDE launcher for Debian's OpenSSH—a softer landing for Windows admins moving to Linux.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

SSHShift

Shift from Windows key → PuTTY → Enter → host → Enter to Debian's OpenSSH—without a hard landing.

SSHShift is a profile-free KDE launcher for OpenSSH, built for Windows administrators moving their daily work to Debian. It provides a familiar “enter a host and connect” window, then gets out of the way and lets the system's real ssh client run inside Konsole.

The Shift suite

ToolFamiliar starting pointDebian engine
RDPShiftAn mstsc-style “enter a computer and connect” workflowFreeRDP
SSHShiftWindows key → PuTTY → Enter → host → Enter, made native to KDEOpenSSH + Konsole
MapShiftA familiar “map network drive” path into KDE applicationsKDE KIO SMB + KIO-FUSE
ServiceShiftA services.msc-style overview with familiar service controlssystemd + PolicyKit
TaskShiftA Task Scheduler-style overview with safe schedule editingsystemd timers + PolicyKit

SSHShift supports Debian 13 with KDE Plasma and Wayland.

Why it exists

Debian already ships excellent administration tools, but a command prompt can be an unnecessarily abrupt first step for administrators arriving from Windows. SSHShift provides a softer landing without replacing OpenSSH, inventing a new protocol stack, or locking users into its interface.

The Advanced options panel shows the equivalent ssh command for the current choices. The launcher can therefore act as training wheels: use the graphical workflow today and take the same command to a terminal whenever you are ready.

Updates stay with Debian

SSHShift does not bundle its own SSH implementation. It launches the OpenSSH and Konsole packages maintained by Debian, so normal apt upgrades deliver their security and bug fixes through the same trusted update path as the rest of the system. There is no separate full client, private protocol copy, or extra updater that can quietly fall behind.

The small wrapper may occasionally need a compatibility or interface update, but the security-sensitive SSH engine remains Debian's package—not frozen inside SSHShift.

Behavior and privacy

  • No connection profiles, recent-host list, saved usernames, or saved passwords.
  • Destination and optional jump-host details have separate cards on the main screen, each pairing its Host and Username fields clearly. Host fields also accept [username@]hostname[:port] notation.
  • Authentication is performed directly by OpenSSH in Konsole. SSHShift never asks for or handles the password.
  • The hostname, username, jump host, and options are supplied through a private OpenSSH configuration under /run/user/$UID, not command-line arguments.
  • The private runtime directory is removed when the Konsole session ends.
  • Persistent host-key lookup uses a keyed HMAC of the normalized hostname and port as an opaque identity.
  • The random HMAC key is held in KDE Wallet.
  • The real hostname exists in a private known-hosts file under /run/user/$UID only while the session is active, so OpenSSH's prompts remain readable.
  • When the session ends, SSHShift translates the transient hostname back to its opaque identity before updating persistent trust.
  • OpenSSH asks before trusting a host for the first time, silently accepts an unchanged key, and refuses a changed key.
  • SSH agent and X11 forwarding are off by default and reset after each launch.
  • An explicitly selected identity file and jump host apply only to the current connection.

The persistent known-host database is stored at $XDG_DATA_HOME/ssh-shift/known_hosts, normally ~/.local/share/ssh-shift/known_hosts. It contains public host keys indexed by KDE-Wallet-keyed opaque aliases—not server names.

Installation on Debian 13

Install the runtime dependencies:

sudo apt install openssh-client konsole python3-dbus python3-pyqt6

Then install SSHShift for the current user:

./install.sh

The application appears as SSHShift in Plasma's application menu. The installer defaults to ~/.local; set PREFIX to choose another user prefix.

To uninstall the launcher:

./uninstall.sh

Uninstalling deliberately preserves the known-host database and KDE Wallet key so reinstalling does not silently discard host-key-change protection.

Connection options

  • Identity file: selects one private key for this connection. When empty, OpenSSH uses its normal default keys and SSH agent.
  • Jump host: routes through a bastion using OpenSSH ProxyJump; it is on the main screen because bastions are part of many administrators' daily workflow. A separate Jump username field is provided, while username@host notation remains supported. Its identity is protected in the same known-host database.
  • Agent forwarding: off by default because a privileged user on the remote host could use the forwarded agent while the connection is active.
  • X11 forwarding: off by default; when enabled, SSHShift requests OpenSSH's untrusted X11 mode.
  • Equivalent command: shows the ordinary OpenSSH command represented by the selected options in the Advanced panel.

If Konsole needs time to start, SSHShift displays a cancellable progress window instead of appearing unresponsive.

Testing

python3 -m unittest discover -s tests -v
python3 -m py_compile ssh-shift

The tests cover endpoint validation, configuration-injection defenses, native UI defaults, command previews, HMAC host aliases, private file permissions, OpenSSH configuration parsing, and destination-free launcher arguments.

Threat-model boundaries

SSHShift prevents this launcher and OpenSSH's user known-host file from retaining recoverable destination names. It cannot hide a live connection from DNS, network equipment, the destination, the operating system, or an attacker able to inspect process memory or an unlocked KDE Wallet. See SECURITY.md for details.

OpenSSH remains responsible for SSH cryptography, authentication, protocol compatibility, host-key validation, and the remote session.

License

MIT. See LICENSE.

About

A privacy-conscious, profile-free KDE launcher for Debian's OpenSSH—a softer landing for Windows admins moving to Linux.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

SSHShift

Shift from Windows key → PuTTY → Enter → host → Enter to Debian's OpenSSH—without a hard landing.

SSHShift is a profile-free KDE launcher for OpenSSH, built for Windows administrators moving their daily work to Debian. It provides a familiar “enter a host and connect” window, then gets out of the way and lets the system's real ssh client run inside Konsole.

The Shift suite

ToolFamiliar starting pointDebian engine
RDPShiftAn mstsc-style “enter a computer and connect” workflowFreeRDP
SSHShiftWindows key → PuTTY → Enter → host → Enter, made native to KDEOpenSSH + Konsole
MapShiftA familiar “map network drive” path into KDE applicationsKDE KIO SMB + KIO-FUSE
ServiceShiftA services.msc-style overview with familiar service controlssystemd + PolicyKit
TaskShiftA Task Scheduler-style overview with safe schedule editingsystemd timers + PolicyKit

SSHShift supports Debian 13 with KDE Plasma and Wayland.

Why it exists

Debian already ships excellent administration tools, but a command prompt can be an unnecessarily abrupt first step for administrators arriving from Windows. SSHShift provides a softer landing without replacing OpenSSH, inventing a new protocol stack, or locking users into its interface.

The Advanced options panel shows the equivalent ssh command for the current choices. The launcher can therefore act as training wheels: use the graphical workflow today and take the same command to a terminal whenever you are ready.

Updates stay with Debian

SSHShift does not bundle its own SSH implementation. It launches the OpenSSH and Konsole packages maintained by Debian, so normal apt upgrades deliver their security and bug fixes through the same trusted update path as the rest of the system. There is no separate full client, private protocol copy, or extra updater that can quietly fall behind.

The small wrapper may occasionally need a compatibility or interface update, but the security-sensitive SSH engine remains Debian's package—not frozen inside SSHShift.

Behavior and privacy

  • No connection profiles, recent-host list, saved usernames, or saved passwords.
  • Destination and optional jump-host details have separate cards on the main screen, each pairing its Host and Username fields clearly. Host fields also accept [username@]hostname[:port] notation.
  • Authentication is performed directly by OpenSSH in Konsole. SSHShift never asks for or handles the password.
  • The hostname, username, jump host, and options are supplied through a private OpenSSH configuration under /run/user/$UID, not command-line arguments.
  • The private runtime directory is removed when the Konsole session ends.
  • Persistent host-key lookup uses a keyed HMAC of the normalized hostname and port as an opaque identity.
  • The random HMAC key is held in KDE Wallet.
  • The real hostname exists in a private known-hosts file under /run/user/$UID only while the session is active, so OpenSSH's prompts remain readable.
  • When the session ends, SSHShift translates the transient hostname back to its opaque identity before updating persistent trust.
  • OpenSSH asks before trusting a host for the first time, silently accepts an unchanged key, and refuses a changed key.
  • SSH agent and X11 forwarding are off by default and reset after each launch.
  • An explicitly selected identity file and jump host apply only to the current connection.

The persistent known-host database is stored at $XDG_DATA_HOME/ssh-shift/known_hosts, normally ~/.local/share/ssh-shift/known_hosts. It contains public host keys indexed by KDE-Wallet-keyed opaque aliases—not server names.

Installation on Debian 13

Install the runtime dependencies:

sudo apt install openssh-client konsole python3-dbus python3-pyqt6

Then install SSHShift for the current user:

./install.sh

The application appears as SSHShift in Plasma's application menu. The installer defaults to ~/.local; set PREFIX to choose another user prefix.

To uninstall the launcher:

./uninstall.sh

Uninstalling deliberately preserves the known-host database and KDE Wallet key so reinstalling does not silently discard host-key-change protection.

Connection options

  • Identity file: selects one private key for this connection. When empty, OpenSSH uses its normal default keys and SSH agent.
  • Jump host: routes through a bastion using OpenSSH ProxyJump; it is on the main screen because bastions are part of many administrators' daily workflow. A separate Jump username field is provided, while username@host notation remains supported. Its identity is protected in the same known-host database.
  • Agent forwarding: off by default because a privileged user on the remote host could use the forwarded agent while the connection is active.
  • X11 forwarding: off by default; when enabled, SSHShift requests OpenSSH's untrusted X11 mode.
  • Equivalent command: shows the ordinary OpenSSH command represented by the selected options in the Advanced panel.

If Konsole needs time to start, SSHShift displays a cancellable progress window instead of appearing unresponsive.

Testing

python3 -m unittest discover -s tests -v
python3 -m py_compile ssh-shift

The tests cover endpoint validation, configuration-injection defenses, native UI defaults, command previews, HMAC host aliases, private file permissions, OpenSSH configuration parsing, and destination-free launcher arguments.

Threat-model boundaries

SSHShift prevents this launcher and OpenSSH's user known-host file from retaining recoverable destination names. It cannot hide a live connection from DNS, network equipment, the destination, the operating system, or an attacker able to inspect process memory or an unlocked KDE Wallet. See SECURITY.md for details.

OpenSSH remains responsible for SSH cryptography, authentication, protocol compatibility, host-key validation, and the remote session.

License

MIT. See LICENSE.

About

A privacy-conscious, profile-free KDE launcher for Debian's OpenSSH—a softer landing for Windows admins moving to Linux.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

SSHShift

Shift from Windows key → PuTTY → Enter → host → Enter to Debian's OpenSSH—without a hard landing.

SSHShift is a profile-free KDE launcher for OpenSSH, built for Windows administrators moving their daily work to Debian. It provides a familiar “enter a host and connect” window, then gets out of the way and lets the system's real ssh client run inside Konsole.

The Shift suite

ToolFamiliar starting pointDebian engine
RDPShiftAn mstsc-style “enter a computer and connect” workflowFreeRDP
SSHShiftWindows key → PuTTY → Enter → host → Enter, made native to KDEOpenSSH + Konsole
MapShiftA familiar “map network drive” path into KDE applicationsKDE KIO SMB + KIO-FUSE
ServiceShiftA services.msc-style overview with familiar service controlssystemd + PolicyKit
TaskShiftA Task Scheduler-style overview with safe schedule editingsystemd timers + PolicyKit

SSHShift supports Debian 13 with KDE Plasma and Wayland.

Why it exists

Debian already ships excellent administration tools, but a command prompt can be an unnecessarily abrupt first step for administrators arriving from Windows. SSHShift provides a softer landing without replacing OpenSSH, inventing a new protocol stack, or locking users into its interface.

The Advanced options panel shows the equivalent ssh command for the current choices. The launcher can therefore act as training wheels: use the graphical workflow today and take the same command to a terminal whenever you are ready.

Updates stay with Debian

SSHShift does not bundle its own SSH implementation. It launches the OpenSSH and Konsole packages maintained by Debian, so normal apt upgrades deliver their security and bug fixes through the same trusted update path as the rest of the system. There is no separate full client, private protocol copy, or extra updater that can quietly fall behind.

The small wrapper may occasionally need a compatibility or interface update, but the security-sensitive SSH engine remains Debian's package—not frozen inside SSHShift.

Behavior and privacy

  • No connection profiles, recent-host list, saved usernames, or saved passwords.
  • Destination and optional jump-host details have separate cards on the main screen, each pairing its Host and Username fields clearly. Host fields also accept [username@]hostname[:port] notation.
  • Authentication is performed directly by OpenSSH in Konsole. SSHShift never asks for or handles the password.
  • The hostname, username, jump host, and options are supplied through a private OpenSSH configuration under /run/user/$UID, not command-line arguments.
  • The private runtime directory is removed when the Konsole session ends.
  • Persistent host-key lookup uses a keyed HMAC of the normalized hostname and port as an opaque identity.
  • The random HMAC key is held in KDE Wallet.
  • The real hostname exists in a private known-hosts file under /run/user/$UID only while the session is active, so OpenSSH's prompts remain readable.
  • When the session ends, SSHShift translates the transient hostname back to its opaque identity before updating persistent trust.
  • OpenSSH asks before trusting a host for the first time, silently accepts an unchanged key, and refuses a changed key.
  • SSH agent and X11 forwarding are off by default and reset after each launch.
  • An explicitly selected identity file and jump host apply only to the current connection.

The persistent known-host database is stored at $XDG_DATA_HOME/ssh-shift/known_hosts, normally ~/.local/share/ssh-shift/known_hosts. It contains public host keys indexed by KDE-Wallet-keyed opaque aliases—not server names.

Installation on Debian 13

Install the runtime dependencies:

sudo apt install openssh-client konsole python3-dbus python3-pyqt6

Then install SSHShift for the current user:

./install.sh

The application appears as SSHShift in Plasma's application menu. The installer defaults to ~/.local; set PREFIX to choose another user prefix.

To uninstall the launcher:

./uninstall.sh

Uninstalling deliberately preserves the known-host database and KDE Wallet key so reinstalling does not silently discard host-key-change protection.

Connection options

  • Identity file: selects one private key for this connection. When empty, OpenSSH uses its normal default keys and SSH agent.
  • Jump host: routes through a bastion using OpenSSH ProxyJump; it is on the main screen because bastions are part of many administrators' daily workflow. A separate Jump username field is provided, while username@host notation remains supported. Its identity is protected in the same known-host database.
  • Agent forwarding: off by default because a privileged user on the remote host could use the forwarded agent while the connection is active.
  • X11 forwarding: off by default; when enabled, SSHShift requests OpenSSH's untrusted X11 mode.
  • Equivalent command: shows the ordinary OpenSSH command represented by the selected options in the Advanced panel.

If Konsole needs time to start, SSHShift displays a cancellable progress window instead of appearing unresponsive.

Testing

python3 -m unittest discover -s tests -v
python3 -m py_compile ssh-shift

The tests cover endpoint validation, configuration-injection defenses, native UI defaults, command previews, HMAC host aliases, private file permissions, OpenSSH configuration parsing, and destination-free launcher arguments.

Threat-model boundaries

SSHShift prevents this launcher and OpenSSH's user known-host file from retaining recoverable destination names. It cannot hide a live connection from DNS, network equipment, the destination, the operating system, or an attacker able to inspect process memory or an unlocked KDE Wallet. See SECURITY.md for details.

OpenSSH remains responsible for SSH cryptography, authentication, protocol compatibility, host-key validation, and the remote session.

License

MIT. See LICENSE.

About

A privacy-conscious, profile-free KDE launcher for Debian's OpenSSH—a softer landing for Windows admins moving to Linux.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

SSHShift

Shift from Windows key → PuTTY → Enter → host → Enter to Debian's OpenSSH—without a hard landing.

SSHShift is a profile-free KDE launcher for OpenSSH, built for Windows administrators moving their daily work to Debian. It provides a familiar “enter a host and connect” window, then gets out of the way and lets the system's real ssh client run inside Konsole.

The Shift suite

ToolFamiliar starting pointDebian engine
RDPShiftAn mstsc-style “enter a computer and connect” workflowFreeRDP
SSHShiftWindows key → PuTTY → Enter → host → Enter, made native to KDEOpenSSH + Konsole
MapShiftA familiar “map network drive” path into KDE applicationsKDE KIO SMB + KIO-FUSE
ServiceShiftA services.msc-style overview with familiar service controlssystemd + PolicyKit
TaskShiftA Task Scheduler-style overview with safe schedule editingsystemd timers + PolicyKit

SSHShift supports Debian 13 with KDE Plasma and Wayland.

Why it exists

Debian already ships excellent administration tools, but a command prompt can be an unnecessarily abrupt first step for administrators arriving from Windows. SSHShift provides a softer landing without replacing OpenSSH, inventing a new protocol stack, or locking users into its interface.

The Advanced options panel shows the equivalent ssh command for the current choices. The launcher can therefore act as training wheels: use the graphical workflow today and take the same command to a terminal whenever you are ready.

Updates stay with Debian

SSHShift does not bundle its own SSH implementation. It launches the OpenSSH and Konsole packages maintained by Debian, so normal apt upgrades deliver their security and bug fixes through the same trusted update path as the rest of the system. There is no separate full client, private protocol copy, or extra updater that can quietly fall behind.

The small wrapper may occasionally need a compatibility or interface update, but the security-sensitive SSH engine remains Debian's package—not frozen inside SSHShift.

Behavior and privacy

  • No connection profiles, recent-host list, saved usernames, or saved passwords.
  • Destination and optional jump-host details have separate cards on the main screen, each pairing its Host and Username fields clearly. Host fields also accept [username@]hostname[:port] notation.
  • Authentication is performed directly by OpenSSH in Konsole. SSHShift never asks for or handles the password.
  • The hostname, username, jump host, and options are supplied through a private OpenSSH configuration under /run/user/$UID, not command-line arguments.
  • The private runtime directory is removed when the Konsole session ends.
  • Persistent host-key lookup uses a keyed HMAC of the normalized hostname and port as an opaque identity.
  • The random HMAC key is held in KDE Wallet.
  • The real hostname exists in a private known-hosts file under /run/user/$UID only while the session is active, so OpenSSH's prompts remain readable.
  • When the session ends, SSHShift translates the transient hostname back to its opaque identity before updating persistent trust.
  • OpenSSH asks before trusting a host for the first time, silently accepts an unchanged key, and refuses a changed key.
  • SSH agent and X11 forwarding are off by default and reset after each launch.
  • An explicitly selected identity file and jump host apply only to the current connection.

The persistent known-host database is stored at $XDG_DATA_HOME/ssh-shift/known_hosts, normally ~/.local/share/ssh-shift/known_hosts. It contains public host keys indexed by KDE-Wallet-keyed opaque aliases—not server names.

Installation on Debian 13

Install the runtime dependencies:

sudo apt install openssh-client konsole python3-dbus python3-pyqt6

Then install SSHShift for the current user:

./install.sh

The application appears as SSHShift in Plasma's application menu. The installer defaults to ~/.local; set PREFIX to choose another user prefix.

To uninstall the launcher:

./uninstall.sh

Uninstalling deliberately preserves the known-host database and KDE Wallet key so reinstalling does not silently discard host-key-change protection.

Connection options

  • Identity file: selects one private key for this connection. When empty, OpenSSH uses its normal default keys and SSH agent.
  • Jump host: routes through a bastion using OpenSSH ProxyJump; it is on the main screen because bastions are part of many administrators' daily workflow. A separate Jump username field is provided, while username@host notation remains supported. Its identity is protected in the same known-host database.
  • Agent forwarding: off by default because a privileged user on the remote host could use the forwarded agent while the connection is active.
  • X11 forwarding: off by default; when enabled, SSHShift requests OpenSSH's untrusted X11 mode.
  • Equivalent command: shows the ordinary OpenSSH command represented by the selected options in the Advanced panel.

If Konsole needs time to start, SSHShift displays a cancellable progress window instead of appearing unresponsive.

Testing

python3 -m unittest discover -s tests -v
python3 -m py_compile ssh-shift

The tests cover endpoint validation, configuration-injection defenses, native UI defaults, command previews, HMAC host aliases, private file permissions, OpenSSH configuration parsing, and destination-free launcher arguments.

Threat-model boundaries

SSHShift prevents this launcher and OpenSSH's user known-host file from retaining recoverable destination names. It cannot hide a live connection from DNS, network equipment, the destination, the operating system, or an attacker able to inspect process memory or an unlocked KDE Wallet. See SECURITY.md for details.

OpenSSH remains responsible for SSH cryptography, authentication, protocol compatibility, host-key validation, and the remote session.

License

MIT. See LICENSE.

About

A privacy-conscious, profile-free KDE launcher for Debian's OpenSSH—a softer landing for Windows admins moving to Linux.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

SSHShift

Shift from Windows key → PuTTY → Enter → host → Enter to Debian's OpenSSH—without a hard landing.

SSHShift is a profile-free KDE launcher for OpenSSH, built for Windows administrators moving their daily work to Debian. It provides a familiar “enter a host and connect” window, then gets out of the way and lets the system's real ssh client run inside Konsole.

The Shift suite

ToolFamiliar starting pointDebian engine
RDPShiftAn mstsc-style “enter a computer and connect” workflowFreeRDP
SSHShiftWindows key → PuTTY → Enter → host → Enter, made native to KDEOpenSSH + Konsole
MapShiftA familiar “map network drive” path into KDE applicationsKDE KIO SMB + KIO-FUSE
ServiceShiftA services.msc-style overview with familiar service controlssystemd + PolicyKit
TaskShiftA Task Scheduler-style overview with safe schedule editingsystemd timers + PolicyKit

SSHShift supports Debian 13 with KDE Plasma and Wayland.

Why it exists

Debian already ships excellent administration tools, but a command prompt can be an unnecessarily abrupt first step for administrators arriving from Windows. SSHShift provides a softer landing without replacing OpenSSH, inventing a new protocol stack, or locking users into its interface.

The Advanced options panel shows the equivalent ssh command for the current choices. The launcher can therefore act as training wheels: use the graphical workflow today and take the same command to a terminal whenever you are ready.

Updates stay with Debian

SSHShift does not bundle its own SSH implementation. It launches the OpenSSH and Konsole packages maintained by Debian, so normal apt upgrades deliver their security and bug fixes through the same trusted update path as the rest of the system. There is no separate full client, private protocol copy, or extra updater that can quietly fall behind.

The small wrapper may occasionally need a compatibility or interface update, but the security-sensitive SSH engine remains Debian's package—not frozen inside SSHShift.

Behavior and privacy

  • No connection profiles, recent-host list, saved usernames, or saved passwords.
  • Destination and optional jump-host details have separate cards on the main screen, each pairing its Host and Username fields clearly. Host fields also accept [username@]hostname[:port] notation.
  • Authentication is performed directly by OpenSSH in Konsole. SSHShift never asks for or handles the password.
  • The hostname, username, jump host, and options are supplied through a private OpenSSH configuration under /run/user/$UID, not command-line arguments.
  • The private runtime directory is removed when the Konsole session ends.
  • Persistent host-key lookup uses a keyed HMAC of the normalized hostname and port as an opaque identity.
  • The random HMAC key is held in KDE Wallet.
  • The real hostname exists in a private known-hosts file under /run/user/$UID only while the session is active, so OpenSSH's prompts remain readable.
  • When the session ends, SSHShift translates the transient hostname back to its opaque identity before updating persistent trust.
  • OpenSSH asks before trusting a host for the first time, silently accepts an unchanged key, and refuses a changed key.
  • SSH agent and X11 forwarding are off by default and reset after each launch.
  • An explicitly selected identity file and jump host apply only to the current connection.

The persistent known-host database is stored at $XDG_DATA_HOME/ssh-shift/known_hosts, normally ~/.local/share/ssh-shift/known_hosts. It contains public host keys indexed by KDE-Wallet-keyed opaque aliases—not server names.

Installation on Debian 13

Install the runtime dependencies:

sudo apt install openssh-client konsole python3-dbus python3-pyqt6

Then install SSHShift for the current user:

./install.sh

The application appears as SSHShift in Plasma's application menu. The installer defaults to ~/.local; set PREFIX to choose another user prefix.

To uninstall the launcher:

./uninstall.sh

Uninstalling deliberately preserves the known-host database and KDE Wallet key so reinstalling does not silently discard host-key-change protection.

Connection options

  • Identity file: selects one private key for this connection. When empty, OpenSSH uses its normal default keys and SSH agent.
  • Jump host: routes through a bastion using OpenSSH ProxyJump; it is on the main screen because bastions are part of many administrators' daily workflow. A separate Jump username field is provided, while username@host notation remains supported. Its identity is protected in the same known-host database.
  • Agent forwarding: off by default because a privileged user on the remote host could use the forwarded agent while the connection is active.
  • X11 forwarding: off by default; when enabled, SSHShift requests OpenSSH's untrusted X11 mode.
  • Equivalent command: shows the ordinary OpenSSH command represented by the selected options in the Advanced panel.

If Konsole needs time to start, SSHShift displays a cancellable progress window instead of appearing unresponsive.

Testing

python3 -m unittest discover -s tests -v
python3 -m py_compile ssh-shift

The tests cover endpoint validation, configuration-injection defenses, native UI defaults, command previews, HMAC host aliases, private file permissions, OpenSSH configuration parsing, and destination-free launcher arguments.

Threat-model boundaries

SSHShift prevents this launcher and OpenSSH's user known-host file from retaining recoverable destination names. It cannot hide a live connection from DNS, network equipment, the destination, the operating system, or an attacker able to inspect process memory or an unlocked KDE Wallet. See SECURITY.md for details.

OpenSSH remains responsible for SSH cryptography, authentication, protocol compatibility, host-key validation, and the remote session.

License

MIT. See LICENSE.

About

A privacy-conscious, profile-free KDE launcher for Debian's OpenSSH—a softer landing for Windows admins moving to Linux.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages