{"id":7098,"date":"2022-03-23T12:02:53","date_gmt":"2022-03-23T09:02:53","guid":{"rendered":"https:\/\/vasexperts.com\/?p=7098"},"modified":"2025-08-13T12:23:33","modified_gmt":"2025-08-13T09:23:33","slug":"doh-what-is-going-on-with-adaptation","status":"publish","type":"post","link":"https:\/\/vasexperts.com\/br\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/","title":{"rendered":"DNS-over-HTTPS &#8211; o que est\u00e1 acontecendo com a adapta\u00e7\u00e3o"},"content":{"rendered":"<h2>Uma tecnologia pol\u00eamica<\/h2>\r\nO DNS-over-HTTPS \u00e9 criticado por \u00f3rg\u00e3os reguladores, empresas de telecomunica\u00e7\u00f5es, representantes de registros da Internet e at\u00e9 mesmo pelo pr\u00f3prio autor do sistema de nomes de dom\u00ednio. Entre os argumentos est\u00e3o a administra\u00e7\u00e3o complicada e os <a href=\"https:\/\/tools.ietf.org\/id\/draft-reid-doh-operator-00.html\" rel=\"noopener noreferrer nofollow\">atrasos<\/a> nas redes de distribui\u00e7\u00e3o de conte\u00fado. Ao mesmo tempo, algumas das implementa\u00e7\u00f5es de protocolo ignoram as regras descritas em \/etc\/nsswitch.conf. Portanto, o gerenciamento do DNS \u00e9 <a href=\"https:\/\/ungleich.ch\/en-us\/cms\/blog\/2019\/09\/11\/turn-off-doh-firefox\/\" rel=\"noopener noreferrer nofollow\">transferido<\/a> do n\u00edvel do sistema operacional para o n\u00edvel do aplicativo, o que pode levar a uma confus\u00e3o entre os servi\u00e7os.\r\n\r\nAl\u00e9m disso, argumenta-se que esse protocolo cria a amea\u00e7a de vazamento de dados pessoais. O DNS-over-HTTPS criptografa as informa\u00e7\u00f5es sobre os recursos visitados, mas elas ainda est\u00e3o dispon\u00edveis para um servidor que processa a solicita\u00e7\u00e3o. Nesse contexto, h\u00e1 preocupa\u00e7\u00f5es com a credibilidade do provedor DoH. Esse \u00e9 um dos motivos pelos quais a Ag\u00eancia de Seguran\u00e7a Nacional dos EUA <a href=\"https:\/\/www.zdnet.com\/article\/nsa-warns-against-using-doh-inside-enterprise-networks\/\" rel=\"noopener noreferrer nofollow\">recomenda<\/a> n\u00e3o usar o DNS-over-HTTPS em redes corporativas e dar mais aten\u00e7\u00e3o \u00e0s solu\u00e7\u00f5es auto-hospedadas.\r\n\r\n<h2>Passo a passo<\/h2>\r\nA dissemina\u00e7\u00e3o bastante lenta da tecnologia parece ser o resultado da dura ret\u00f3rica contra ela. Atualmente, um tr\u00e1fego de DNS \u201ccl\u00e1ssico\u201d \u00e9 <a href=\"https:\/\/blog.apnic.net\/2021\/09\/13\/the-prevalence-of-dns-over-https\/\" rel=\"noopener noreferrer nofollow\">tr\u00eas vezes maior<\/a> do que um tr\u00e1fego criptografado. No entanto, a situa\u00e7\u00e3o est\u00e1 mudando gradualmente \u2013 de acordo com os principais ISPs e empresas de IS, o tr\u00e1fego de DoH aumentou nos \u00faltimos anos. Isso \u00e9 especialmente percept\u00edvel no Brasil, nos Estados Unidos, na It\u00e1lia, na Argentina e na Espanha (consulte a p\u00e1gina 10 do estudo sobre esse t\u00f3pico).\r\n\r\n[important]Essa tend\u00eancia est\u00e1 relacionada \u00e0 ativa\u00e7\u00e3o do DNS-over-HTTPS por padr\u00e3o nos principais navegadores. Assim, os desenvolvedores do Firefox inclu\u00edram um novo protocolo para os usu\u00e1rios americanos em 2019 e em 2021 para os usu\u00e1rios do Canad\u00e1. No segundo caso, o projeto foi implementado em parceria com o provedor CIRA do DoH.[\/important]\r\n\r\nDe acordo com os representantes do \u201cFirefox\u201d, a empresa n\u00e3o armazena registros por mais de um dia, n\u00e3o transfere dados de usu\u00e1rios para terceiros e aplica obrigatoriamente a tecnologia DNS Query Name Minimisation (RFC 7816).\r\n\r\nA capacidade de trabalhar com DNS-over-HTTPS foi <a href=\"https:\/\/www.zdnet.com\/article\/dns-over-https-will-eventually-roll-out-in-all-major-browsers-despite-isp-opposition\/\" rel=\"noopener noreferrer nofollow\">tamb\u00e9m adicionada<\/a> ao Chrome, Edge e Brave. A funcionalidade correspondente tamb\u00e9m est\u00e1 implementada no firmware do roteador, tanto comercial quanto de c\u00f3digo aberto (como o OpenWRT).\r\n\r\n<noscript><img loading=\"lazy\" decoding=\"async\" src=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png\" alt=\"browsers with DoH\" width=\"820\" height=\"312\" class=\"alignnone size-full wp-image-7111\" srcset=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png 820w, \/wp-content\/uploads\/2022\/03\/browsers-with-doh-300x114.png 300w, \/wp-content\/uploads\/2022\/03\/browsers-with-doh-768x292.png 768w\" sizes=\"(max-width: 820px) 100vw, 820px\"><\/noscript><img loading=\"lazy\" decoding=\"async\" src=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png\" alt=\"browsers with DoH\" width=\"820\" height=\"312\" class=\"alignnone size-full wp-image-7111 lazyload\" sizes=\"(max-width: 820px) 100vw, 820px\" data-src=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png\" data-srcset=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png 820w, \/wp-content\/uploads\/2022\/03\/browsers-with-doh-300x114.png 300w, \/wp-content\/uploads\/2022\/03\/browsers-with-doh-768x292.png 768w\">\r\n\r\nOs entusiastas tamb\u00e9m est\u00e3o contribuindo para o desenvolvimento da tecnologia. Por exemplo, engenheiros da APNIC <a href=\"https:\/\/blog.apnic.net\/2021\/09\/13\/the-prevalence-of-dns-over-https\/\" rel=\"noopener noreferrer nofollow\">fizeram uma varredura<\/a> no espa\u00e7o de endere\u00e7os IPv4, depois procuraram portas 443 abertas e as testaram com um <a href=\"https:\/\/github.com\/stratosphereips\/DoH-Research\/tree\/main\/nmap-script\" rel=\"noopener noreferrer nofollow\">script especial<\/a>. Eles encontraram mais de 930 resolvedores DoH, um quarto dos quais implantados em servidores dom\u00e9sticos e provavelmente usados em projetos privados (esses sistemas n\u00e3o tinham registros de zonas de visualiza\u00e7\u00e3o posterior).\r\n\r\n<h2>Outras op\u00e7\u00f5es<\/h2>\r\nMuito provavelmente, o DoH ser\u00e1 implementado por mais e mais desenvolvedores. No entanto, isso n\u00e3o significa que ser\u00e1 a solu\u00e7\u00e3o \u201cfinal\u201d para a criptografia de solicita\u00e7\u00f5es de DNS \u2013 outras alternativas est\u00e3o sendo desenvolvidas, al\u00e9m do DNS-over-TLS. Assim, o grupo de trabalho da IETF <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/draft-pauly-dprive-oblivious-doh-03\" rel=\"noopener noreferrer nofollow\">prop\u00f4s<\/a> um padr\u00e3o de c\u00f3digo aberto Oblivious DNS-over-HTTPS (ODoH), que <a href=\"https:\/\/blog.cloudflare.com\/oblivious-dns\/\" rel=\"noopener noreferrer nofollow\">permite<\/a> ocultar o IP dos dispositivos do usu\u00e1rio usando proxies. Nesse caso, o provedor de DNS v\u00ea apenas o endere\u00e7o do link intermedi\u00e1rio.\r\n\r\n[important]O endere\u00e7o IP do cliente \u00e9 conhecido pelo proxy, mas o proxy n\u00e3o pode obter informa\u00e7\u00f5es sobre a solicita\u00e7\u00e3o porque a mensagem est\u00e1 criptografada.[\/important]\r\n\r\nExistem solu\u00e7\u00f5es para a criptografia de recursos para o sistema de nomes de dom\u00ednio com base em outros protocolos, como o QUIC. Mas ainda \u00e9 muito cedo para falar sobre seu uso generalizado. Em particular, mesmo em compara\u00e7\u00e3o com o DNS-over-HTTPS, o volume de tr\u00e1fego do DNS-over-QUIC \u00e9 <a href=\"https:\/\/blog.apnic.net\/2021\/09\/13\/the-prevalence-of-dns-over-https\/\" rel=\"noopener noreferrer nofollow\">incrivelmente pequeno<\/a>. A implementa\u00e7\u00e3o pr\u00e1tica de tais sistemas tamb\u00e9m \u00e9 question\u00e1vel, j\u00e1 que, no futuro, o DNS-over-HTTPS oferecer\u00e1 <a href=\"https:\/\/adguard.com\/en\/blog\/dns-over-quic.html\" rel=\"noopener noreferrer nofollow\">suporte<\/a> ao QUIC (\u00e0s custas do HTTP\/3).\r\n\r\n\u00c9 muito cedo para dizer qual tecnologia de criptografia de solicita\u00e7\u00f5es de DNS ser\u00e1 implementada, mas isso definitivamente pode levar algumas d\u00e9cadas de qualquer maneira.\r\n\r\n[subscription id=\u201d 11987\u2033]Assine nosso boletim informativo e fique atualizado sobre os \u00faltimos desenvolvimentos e ofertas especiais.[\/subscription]","protected":false},"excerpt":{"rendered":"<p>Desde o in\u00edcio, esse protocolo tem sido muito controverso na comunidade de TI. Algumas pessoas acreditam que o DoH aumenta a seguran\u00e7a das conex\u00f5es, enquanto outras acham que ele apenas dificulta o trabalho dos administradores de sistemas. De qualquer forma, o DoH \u00e9 usado por um n\u00famero cada vez maior de aplicativos, apesar dos diferentes pontos de vista. Neste artigo, daremos uma olhada mais de perto e lhe diremos o que realmente est\u00e1 acontecendo.<\/p>\n","protected":false},"author":7,"featured_media":7104,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48],"tags":[],"class_list":["post-7098","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-telecom"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>(English) VASExperts<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/\",\"url\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/\",\"name\":\"[:en]DNS-over-HTTPS \u2014 what is going on with the adaptation[:es]DNS-over-HTTPS: qu\u00e9 est\u00e1 pasando con la adaptaci\u00f3n[:fr]DNS-over-HTTPS \u2014 comment se passe l'adaptation[:br]DNS-over-HTTPS \u2014 o que est\u00e1 acontecendo com a adapta\u00e7\u00e3o\",\"isPartOf\":{\"@id\":\"https:\/\/vasexperts.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage\"},\"thumbnailUrl\":\"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg\",\"datePublished\":\"2022-03-23T09:02:53+00:00\",\"dateModified\":\"2025-08-13T09:23:33+00:00\",\"author\":{\"@id\":\"https:\/\/vasexperts.com\/#\/schema\/person\/f4edcaef26fe49b6b59baf8ac5b62170\"},\"description\":\"[:en]DoH is used by more and more applications despite the different points of view. In this article, we will take a closer look at it and tell you what\u2019s really going on.[:es]DoH es utilizado por m\u00e1s y m\u00e1s aplicaciones a pesar de los diferentes puntos de vista. En este art\u00edculo, lo veremos m\u00e1s de cerca y le diremos lo que est\u00e1 pasando en realidad.[:fr]Mais malgr\u00e9 la polarit\u00e9 des points de vue, de plus en plus d'applications utilisent DoH. Nous vous disons ce qui se passe.[:br]O DoH \u00e9 usado por cada vez mais aplica\u00e7\u00f5es, apesar dos diferentes pontos de vista. Neste artigo, vamos analis\u00e1-lo mais de perto e explicar o que realmente est\u00e1 acontecendo.\",\"breadcrumb\":{\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#breadcrumb\"},\"inLanguage\":\"br-PT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"br-PT\",\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage\",\"url\":\"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg\",\"contentUrl\":\"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg\",\"width\":1130,\"height\":472,\"caption\":\"VAS Experts DoH article\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\",\"item\":\"https:\/\/vasexperts.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DNS-over-HTTPS \u2014 what is going on with the adaptation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/vasexperts.com\/#website\",\"url\":\"https:\/\/vasexperts.com\/\",\"name\":\"ITGLOBAL.COM\",\"description\":\"(English) VASExperts\",\"inLanguage\":\"br-PT\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/vasexperts.com\/#\/schema\/person\/f4edcaef26fe49b6b59baf8ac5b62170\",\"name\":\"Elena Rudich\",\"url\":\"https:\/\/vasexperts.com\/br\/blog\/author\/elena-rudich\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"(English) VASExperts","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/","url":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/","name":"[:en]DNS-over-HTTPS \u2014 what is going on with the adaptation[:es]DNS-over-HTTPS: qu\u00e9 est\u00e1 pasando con la adaptaci\u00f3n[:fr]DNS-over-HTTPS \u2014 comment se passe l'adaptation[:br]DNS-over-HTTPS \u2014 o que est\u00e1 acontecendo com a adapta\u00e7\u00e3o","isPartOf":{"@id":"https:\/\/vasexperts.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage"},"image":{"@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage"},"thumbnailUrl":"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg","datePublished":"2022-03-23T09:02:53+00:00","dateModified":"2025-08-13T09:23:33+00:00","author":{"@id":"https:\/\/vasexperts.com\/#\/schema\/person\/f4edcaef26fe49b6b59baf8ac5b62170"},"description":"[:en]DoH is used by more and more applications despite the different points of view. In this article, we will take a closer look at it and tell you what\u2019s really going on.[:es]DoH es utilizado por m\u00e1s y m\u00e1s aplicaciones a pesar de los diferentes puntos de vista. En este art\u00edculo, lo veremos m\u00e1s de cerca y le diremos lo que est\u00e1 pasando en realidad.[:fr]Mais malgr\u00e9 la polarit\u00e9 des points de vue, de plus en plus d'applications utilisent DoH. Nous vous disons ce qui se passe.[:br]O DoH \u00e9 usado por cada vez mais aplica\u00e7\u00f5es, apesar dos diferentes pontos de vista. Neste artigo, vamos analis\u00e1-lo mais de perto e explicar o que realmente est\u00e1 acontecendo.","breadcrumb":{"@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#breadcrumb"},"inLanguage":"br-PT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/"]}]},{"@type":"ImageObject","inLanguage":"br-PT","@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage","url":"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg","contentUrl":"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg","width":1130,"height":472,"caption":"VAS Experts DoH article"},{"@type":"BreadcrumbList","@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430","item":"https:\/\/vasexperts.com\/"},{"@type":"ListItem","position":2,"name":"DNS-over-HTTPS \u2014 what is going on with the adaptation"}]},{"@type":"WebSite","@id":"https:\/\/vasexperts.com\/#website","url":"https:\/\/vasexperts.com\/","name":"ITGLOBAL.COM","description":"(English) VASExperts","inLanguage":"br-PT"},{"@type":"Person","@id":"https:\/\/vasexperts.com\/#\/schema\/person\/f4edcaef26fe49b6b59baf8ac5b62170","name":"Elena Rudich","url":"https:\/\/vasexperts.com\/br\/blog\/author\/elena-rudich\/"}]}},"_links":{"self":[{"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/posts\/7098"}],"collection":[{"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/comments?post=7098"}],"version-history":[{"count":10,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/posts\/7098\/revisions"}],"predecessor-version":[{"id":12973,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/posts\/7098\/revisions\/12973"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/media\/7104"}],"wp:attachment":[{"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/media?parent=7098"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/categories?post=7098"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/tags?post=7098"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}