{"id":7098,"date":"2022-03-23T12:02:53","date_gmt":"2022-03-23T09:02:53","guid":{"rendered":"https:\/\/vasexperts.com\/?p=7098"},"modified":"2025-08-13T12:23:33","modified_gmt":"2025-08-13T09:23:33","slug":"doh-what-is-going-on-with-adaptation","status":"publish","type":"post","link":"https:\/\/vasexperts.com\/fr\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/","title":{"rendered":"DNS-over-HTTPS \u2014 comment se passe l&rsquo;adaptation"},"content":{"rendered":"<h2>Technologie controvers\u00e9e<\/h2>\r\nDNS-over-HTTPS est critiqu\u00e9 par les r\u00e9gulateurs, les t\u00e9l\u00e9coms, les repr\u00e9sentants des registraires Internet, et m\u00eame l\u2019auteur du syst\u00e8me de noms de domaine lui-m\u00eame. Parmi les arguments figurent la complexit\u00e9 de l\u2019administration et <a href=\"https:\/\/tools.ietf.org\/id\/draft-reid-doh-operator-00.html\" rel=\"noopener noreferrer nofollow\">les retards<\/a> dans les r\u00e9seaux de diffusion de contenu. Dans le m\u00eame temps, les impl\u00e9mentations individuelles du protocole ignorent les r\u00e8gles d\u00e9crites dans \/etc\/nsswitch.conf. Ainsi, la gestion du DNS <a href=\"https:\/\/ungleich.ch\/en-us\/cms\/blog\/2019\/09\/11\/turn-off-doh-firefox\/\" rel=\"noopener noreferrer nofollow\">passe<\/a> du niveau du syst\u00e8me d\u2019exploitation au niveau de l\u2019application, ce qui peut cr\u00e9er une confusion entre les services.\r\n\r\nIl y a aussi une opinion que le protocole cr\u00e9e un risque de fuite de donn\u00e9es personnelles. DNS-over-HTTPS crypte les informations sur les ressources visit\u00e9es, mais elles sont toujours disponibles pour le serveur qui traite la demande. Dans ce contexte, il y a un probl\u00e8me de confiance dans le Fournisseur DoH. C\u2019est l\u2019une des raisons pour lesquelles la National Security Agency des \u00c9tats-Unis <a href=\"https:\/\/www.zdnet.com\/article\/nsa-warns-against-using-doh-inside-enterprise-networks\/\" rel=\"noopener noreferrer nofollow\">recommande<\/a> de ne pas utiliser DNS-over-HTTPS sur les r\u00e9seaux d\u2019entreprise et de pr\u00eater attention aux solutions self-hosted.\r\n<h2>Petits progr\u00e8s<\/h2>\r\nLes d\u00e9clarations acerbes \u00e0 l\u2019\u00e9gard de la technologie ont probablement ralenti sa diffusion. Aujourd\u2019hui, le trafic DNS \u00ab classique \u00bb <a href=\"https:\/\/blog.apnic.net\/2021\/09\/13\/the-prevalence-of-dns-over-https\/\" rel=\"noopener noreferrer nofollow\">est trois fois<\/a> sup\u00e9rieur au volume crypt\u00e9. Cependant, la situation \u00e9volue progressivement. Selon les principaux fournisseurs de services Internet et les soci\u00e9t\u00e9s de s\u00e9curit\u00e9 de l\u2019information, le trafic DoH a augment\u00e9 ces derni\u00e8res ann\u00e9es. Cela est perceptible au Br\u00e9sil, aux \u00c9tats-Unis, en Italie, en Argentine et en Espagne (voir page 10 de l\u2019\u00e9tude sur ce sujet).\r\n\r\n[important]La tendance \u00e0 la hausse est li\u00e9e \u00e0 l\u2019activation de DNS-over-HTTPS par d\u00e9faut dans les principaux navigateurs. Ainsi, en 2019, les d\u00e9veloppeurs de Firefox ont inclus un nouveau protocole pour les utilisateurs am\u00e9ricains, et cette ann\u00e9e \u2014 pour les utilisateurs du Canada. Dans le second cas, le projet a \u00e9t\u00e9 mis en \u0153uvre en partenariat avec le fournisseur du DoH CIRA.[\/important]\r\n\r\nSelon les repr\u00e9sentants de Firefox, la soci\u00e9t\u00e9 ne stocke pas les journaux plus d\u2019une journ\u00e9e, ne transmet pas les donn\u00e9es des utilisateurs \u00e0 des tiers et utilise obligatoirement la technologie DNS Query Name Minimisation (RFC 7816).\r\n\r\nLa possibilit\u00e9 de travailler avec DNS-over-HTTPS a <a href=\"https:\/\/www.zdnet.com\/article\/dns-over-https-will-eventually-roll-out-in-all-major-browsers-despite-isp-opposition\/\" rel=\"noopener noreferrer nofollow\">\u00e9galement \u00e9t\u00e9 ajout\u00e9e<\/a> \u00e0 Chrome, Edge et Brave. La fonctionnalit\u00e9 correspondante est \u00e9galement impl\u00e9ment\u00e9e dans le micrologiciel des routeurs \u00e0 la fois commerciaux et ouverts comme OpenWRT.\r\n\r\n<noscript><img loading=\"lazy\" decoding=\"async\" src=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png\" alt=\"browsers with DoH\" width=\"820\" height=\"312\" class=\"alignnone size-full wp-image-7111\" srcset=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png 820w, \/wp-content\/uploads\/2022\/03\/browsers-with-doh-300x114.png 300w, \/wp-content\/uploads\/2022\/03\/browsers-with-doh-768x292.png 768w\" sizes=\"(max-width: 820px) 100vw, 820px\"><\/noscript><img loading=\"lazy\" decoding=\"async\" src=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png\" alt=\"browsers with DoH\" width=\"820\" height=\"312\" class=\"alignnone size-full wp-image-7111 lazyload\" sizes=\"(max-width: 820px) 100vw, 820px\" data-src=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png\" data-srcset=\"\/wp-content\/uploads\/2022\/03\/browsers-with-doh.png 820w, \/wp-content\/uploads\/2022\/03\/browsers-with-doh-300x114.png 300w, \/wp-content\/uploads\/2022\/03\/browsers-with-doh-768x292.png 768w\">\r\n\r\nLes passionn\u00e9s contribuent \u00e9galement au d\u00e9veloppement de la technologie. En septembre, les ing\u00e9nieurs de l\u2019APNIC ont analys\u00e9 <a href=\"https:\/\/blog.apnic.net\/2021\/09\/13\/the-prevalence-of-dns-over-https\/\" rel=\"noopener noreferrer nofollow\">l\u2019espace d\u2019adresses IPv4<\/a> \u00e0 la recherche de ports 443 ouverts, les ont test\u00e9s avec un <a href=\"https:\/\/github.com\/stratosphereips\/DoH-Research\/tree\/main\/nmap-script\" rel=\"noopener noreferrer nofollow\">script sp\u00e9cial<\/a> et ont trouv\u00e9 plus de 930 r\u00e9solveurs DoH, dont un quart sont d\u00e9ploy\u00e9s sur des serveurs domestiques et probablement utilis\u00e9s dans des projets priv\u00e9s (ces syst\u00e8mes n\u2019ont pas d\u2019enregistrements de visualisation des zones invers\u00e9es).\r\n\r\n<h2>Autres options<\/h2>\r\nDoH sera impl\u00e9ment\u00e9 par de plus en plus de d\u00e9veloppeurs. Mais ce n\u2019est pas un fait qu\u2019il deviendra la solution \u00ab finale \u00bb pour chiffrer les requ\u00eates DNS. En plus du DNS-over-TLS, que nous avons \u00e9voqu\u00e9 dans l\u2019un des articles pr\u00e9c\u00e9dents, d\u2019autres alternatives sont en cours de d\u00e9veloppement. Par exemple, un groupe de travail de l\u2019IETF a <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/draft-pauly-dprive-oblivious-doh-03\" rel=\"noopener noreferrer nofollow\">propos\u00e9<\/a> la norme open source Oblivious DNS-over-HTTPS (ODoH). Il <a href=\"https:\/\/blog.cloudflare.com\/oblivious-dns\/\" rel=\"noopener noreferrer nofollow\">permet<\/a> de masquer les adresses IP des appareils utilisateur \u00e0 l\u2019aide d\u2019un proxy. Dans ce cas, le fournisseur DNS ne voit que l\u2019adresse du lien interm\u00e9diaire.\r\n\r\n[important]L\u2019adresse IP du client est connue du serveur proxy, mais il ne peut pas recevoir d\u2019informations sur la requ\u00eate (car le message est crypt\u00e9).[\/important]\r\n\r\nDes solutions de chiffrement d\u2019acc\u00e8s au syst\u00e8me de noms de domaine bas\u00e9es sur d\u2019autres protocoles apparaissent, comme par exemple le QUIC. Mais il est trop t\u00f4t pour parler de leur large diffusion. En particulier, les volumes de trafic DNS-over-QUIC sont <a href=\"https:\/\/blog.apnic.net\/2021\/09\/13\/the-prevalence-of-dns-over-https\/\" rel=\"noopener noreferrer nofollow\">incroyablement faibles<\/a>, m\u00eame par rapport \u00e0 DNS-over-HTTPS. La mise en \u0153uvre pratique de tels syst\u00e8mes est \u00e9galement discutable, car \u00e0 l\u2019avenir, le DNS-over-HTTPS recevra <a href=\"https:\/\/adguard.com\/en\/blog\/dns-over-quic.html\" rel=\"noopener noreferrer nofollow\">le support<\/a> QUIC [en raison du protocole HTTP\/3].\r\n\r\nIl est trop t\u00f4t pour dire quelle technologie de cryptage DNS sera mise en \u0153uvre. Mais dans tous les cas, cela peut prendre quelques d\u00e9cennies.\r\n\r\n[subscription id=\u00a0\u00bb11987\u2033]Abonnez-vous \u00e0 notre newsletter et restez inform\u00e9 des derniers d\u00e9veloppements et offres sp\u00e9ciales.[\/subscription]","protected":false},"excerpt":{"rendered":"<p>Depuis sa cr\u00e9ation, ce protocole a suscit\u00e9 la controverse dans la communaut\u00e9 informatique. Certains croient que le DoH augmente la s\u00e9curit\u00e9 des connexions, d&rsquo;autres pensent qu&rsquo;il ne fait que compliquer le travail des administrateurs syst\u00e8me. Mais malgr\u00e9 la polarit\u00e9 des points de vue, de plus en plus d&rsquo;applications utilisent DoH. Nous vous disons ce qui se passe.<\/p>\n","protected":false},"author":7,"featured_media":7104,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48],"tags":[],"class_list":["post-7098","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-telecom"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>(English) VASExperts<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/\",\"url\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/\",\"name\":\"[:en]DNS-over-HTTPS \u2014 what is going on with the adaptation[:es]DNS-over-HTTPS: qu\u00e9 est\u00e1 pasando con la adaptaci\u00f3n[:fr]DNS-over-HTTPS \u2014 comment se passe l'adaptation[:br]DNS-over-HTTPS \u2014 o que est\u00e1 acontecendo com a adapta\u00e7\u00e3o\",\"isPartOf\":{\"@id\":\"https:\/\/vasexperts.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage\"},\"thumbnailUrl\":\"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg\",\"datePublished\":\"2022-03-23T09:02:53+00:00\",\"dateModified\":\"2025-08-13T09:23:33+00:00\",\"author\":{\"@id\":\"https:\/\/vasexperts.com\/#\/schema\/person\/f4edcaef26fe49b6b59baf8ac5b62170\"},\"description\":\"[:en]DoH is used by more and more applications despite the different points of view. In this article, we will take a closer look at it and tell you what\u2019s really going on.[:es]DoH es utilizado por m\u00e1s y m\u00e1s aplicaciones a pesar de los diferentes puntos de vista. En este art\u00edculo, lo veremos m\u00e1s de cerca y le diremos lo que est\u00e1 pasando en realidad.[:fr]Mais malgr\u00e9 la polarit\u00e9 des points de vue, de plus en plus d'applications utilisent DoH. Nous vous disons ce qui se passe.[:br]O DoH \u00e9 usado por cada vez mais aplica\u00e7\u00f5es, apesar dos diferentes pontos de vista. Neste artigo, vamos analis\u00e1-lo mais de perto e explicar o que realmente est\u00e1 acontecendo.\",\"breadcrumb\":{\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage\",\"url\":\"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg\",\"contentUrl\":\"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg\",\"width\":1130,\"height\":472,\"caption\":\"VAS Experts DoH article\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\",\"item\":\"https:\/\/vasexperts.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DNS-over-HTTPS \u2014 what is going on with the adaptation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/vasexperts.com\/#website\",\"url\":\"https:\/\/vasexperts.com\/\",\"name\":\"ITGLOBAL.COM\",\"description\":\"(English) VASExperts\",\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/vasexperts.com\/#\/schema\/person\/f4edcaef26fe49b6b59baf8ac5b62170\",\"name\":\"Elena Rudich\",\"url\":\"https:\/\/vasexperts.com\/fr\/blog\/author\/elena-rudich\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"(English) VASExperts","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/","url":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/","name":"[:en]DNS-over-HTTPS \u2014 what is going on with the adaptation[:es]DNS-over-HTTPS: qu\u00e9 est\u00e1 pasando con la adaptaci\u00f3n[:fr]DNS-over-HTTPS \u2014 comment se passe l'adaptation[:br]DNS-over-HTTPS \u2014 o que est\u00e1 acontecendo com a adapta\u00e7\u00e3o","isPartOf":{"@id":"https:\/\/vasexperts.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage"},"image":{"@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage"},"thumbnailUrl":"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg","datePublished":"2022-03-23T09:02:53+00:00","dateModified":"2025-08-13T09:23:33+00:00","author":{"@id":"https:\/\/vasexperts.com\/#\/schema\/person\/f4edcaef26fe49b6b59baf8ac5b62170"},"description":"[:en]DoH is used by more and more applications despite the different points of view. In this article, we will take a closer look at it and tell you what\u2019s really going on.[:es]DoH es utilizado por m\u00e1s y m\u00e1s aplicaciones a pesar de los diferentes puntos de vista. En este art\u00edculo, lo veremos m\u00e1s de cerca y le diremos lo que est\u00e1 pasando en realidad.[:fr]Mais malgr\u00e9 la polarit\u00e9 des points de vue, de plus en plus d'applications utilisent DoH. Nous vous disons ce qui se passe.[:br]O DoH \u00e9 usado por cada vez mais aplica\u00e7\u00f5es, apesar dos diferentes pontos de vista. Neste artigo, vamos analis\u00e1-lo mais de perto e explicar o que realmente est\u00e1 acontecendo.","breadcrumb":{"@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#primaryimage","url":"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg","contentUrl":"\/wp-content\/uploads\/2022\/03\/vas-experts-doh-article.jpg","width":1130,"height":472,"caption":"VAS Experts DoH article"},{"@type":"BreadcrumbList","@id":"https:\/\/vasexperts.com\/blog\/telecom\/doh-what-is-going-on-with-adaptation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430","item":"https:\/\/vasexperts.com\/"},{"@type":"ListItem","position":2,"name":"DNS-over-HTTPS \u2014 what is going on with the adaptation"}]},{"@type":"WebSite","@id":"https:\/\/vasexperts.com\/#website","url":"https:\/\/vasexperts.com\/","name":"ITGLOBAL.COM","description":"(English) VASExperts","inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/vasexperts.com\/#\/schema\/person\/f4edcaef26fe49b6b59baf8ac5b62170","name":"Elena Rudich","url":"https:\/\/vasexperts.com\/fr\/blog\/author\/elena-rudich\/"}]}},"_links":{"self":[{"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/posts\/7098"}],"collection":[{"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/comments?post=7098"}],"version-history":[{"count":10,"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/posts\/7098\/revisions"}],"predecessor-version":[{"id":12973,"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/posts\/7098\/revisions\/12973"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/media\/7104"}],"wp:attachment":[{"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/media?parent=7098"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/categories?post=7098"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vasexperts.com\/fr\/wp-json\/wp\/v2\/tags?post=7098"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}