What is bzib.nelreports.net and deff.nelreports.net in relation to Microsoft Edge?

Anonymous
2023-11-11T06:49:29+00:00

I am a Microsoft Edge user and I have recently noticed that my browser is attempting to connect to bzib.nelreports.net and deff.nelreports.net. My security software, Bitdefender, has flagged these connection attempts due to an expired certificate.

I would like to understand why these connections are being made and whether this is expected behavior for Microsoft Edge. If it is, could you please provide some context as to what bzib.nelreports.net and deff.nelreports.net is used for? If it’s not expected behavior, could anyone advise on the steps I should take to address this issue?

Microsoft Edge | Other | Windows 10

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-11-15T14:00:28+00:00

Note: This issue was fixed on 15 Nov 2023 by updating the site's certificates.

Explanation:

Several certificates used on subdomains of this domain expired last week. Certificate expiration has no impact on security or the end user. Basically, the browser will not be able to submit network error logging reports until the certificate is fixed. Network error logging is an HTML5 feature that helps site owners discover network connectivity issues.

Your security software simply announces "Hey, this certificate is bad", a fact that the browser already determined for itself and responds to by not connecting to the server in question.

Security software provides a redundant warning; the browser will not use connections with expired or invalid certificates.

Subdomain names are random strings of characters with no particular meaning.

The appropriate team has been informed of the certificate expiration and corrected the issue.

Was this answer helpful?

20+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2023-11-16T18:25:14+00:00

This issue was fixed on 11/16 by updating the certificates.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

108 additional answers

Sort by: Most helpful
  1. Anonymous
    2023-11-16T14:31:46+00:00

    It would appear that someone finally fixed the certs, you can go to those sites now without Bitdefender trying to block it. No more notifications.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. JuliaMarvin 22,530 Reputation points Volunteer Moderator
    2023-11-15T17:14:56+00:00

    *.nelreports.net is a Microsoft domain. Several certificates used on the subdomains of this domain expired last week.

    There is no security impact or end-user-impact of the certificate expiration -- Basically, the browser will be unable to submit Network Error Logging reports until the certificate is corrected. Network Error Logging is a HTML5 feature to allow site owners to discover network connectivity problems.

    Your security software is just announcing "Hey, this certificate is bad", a fact that the browser already was determining on its own, and to which it responds by not connecting to the server in question. The security software provides a redundant warning -- the browser will not use connections with expired or invalid certificates.

    The subdomain names are random strings of characters with no particular meaning.

    The relevant team has been notified about the certificate expiration and will correct the issue.

    Thanks Eric Lawrence (ericlaw)!

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2023-11-15T13:58:56+00:00

    This is what GPT-4 has on the issue, as of mid 11/15/2023:

    The mysterious connection attempts to deff.nelreports.net and bzib.nelreports.net by Microsoft Edge that have been flagged by Bitdefender involve a few intriguing elements:

    1. Nature of the Domains: These domains are associated with Microsoft Network Error Logging, which sends requests to check the status of network connections from users' browsers. When the browser sends this information back, Bitdefender checks the certificate status and halts the transmission if the certificate is expired or invalid​​​​.
    2. Microsoft's Ownership and Certificate Expiry: Microsoft owns these domains. The SSL certificates for these domains recently expired. Despite the certificate expiry, there is no indication of malware or harm to devices from these connections. The alert from Bitdefender is triggered by its Online Threat Prevention module, which activates whenever a website without an SSL certificate is accessed, or when a secure website has an invalid security certificate, as in this case​​.
    3. Response and Resolutions: Discussions on Microsoft forums indicate that the issue has been widely reported. The domain extensionwebstorebase.edgesv.net is obsolete, leading Microsoft to allow its certificate to expire. However, Edge, for unknown reasons, continues to call to this domain in relation to certain extensions. The Edge Team is reportedly working on an update to resolve this issue, although there is no estimated time of arrival for this update​​.

    While this information sheds light on the nature of the domains and the reason behind the expired certificates, a definitive statement from Microsoft regarding the resolution of this issue or a timeline for the same was not found in the available sources. It's possible that the situation is still being addressed, and users might have to wait for an official update from Microsoft for a complete resolution.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments