markets.books.microsoft

Anonymous
2019-11-11T02:58:22+00:00

What is markets.books.microsoft

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

94 answers

Sort by: Newest
  1. Anonymous
    2020-03-25T17:50:23+00:00

    Hi there,

    You seem to know a whole lot more than I do. When I was having this problem, I never allowed or white-listed the offending connection. I did pretty much what you did too.  I ignored the bothersome warning until I updated to the new Chrome-based EDGE. Why would moving to the new EDGE stop this BitDefender warning ? I did nothing else other than that and I've never had this problem again. I would really like to understand this. 

    I noticed that when I was on MSN.com with the old Edge browser, I would be nagged and nagged about the connection being blocked but I never noticed any other problem other  than the warning. On other sites, never had any problem.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-03-25T17:29:44+00:00

    Perhaps someone should simply describe what would be the RESULT if allowing the insecure use of the certificate. As we already know, not furnishing an entry to ALLOW or PERMIT an expired certificate to be accepted, any security software in place will default to BLOCK the connection to that resource.

    Therefore, furnishing a system with an explicit ALLOW or PERMIT for the expired certificate would result in: any connection attempt to that resource ONLY FROM ANY MACHINE THAT HAS EXPLICITLY ACCEPTED/PERMITted connections TO THAT RESOURCE (**AND** FROM THAT ENDPOINT). That is, if you have two computers on the same network, but only one of them has ALLOW'd the insecure connection, then ONLY that machine that has allowed the use of the expired certificate will be able to reach the data on that resource. What does that mean? Well, since we don't know WHAT is hosted on that resource, we cannot say for sure. If the data is, indeed, coming from Microsoft, then sure- we can be fairly confident that there is not some malicious script residing there waiting to exploit the machine with which we are connecting.

    I would advise that if one is getting by without whatever is hosted at that resource and the only motivation to take any action is a warning from a security software instance, then the correct action to take would be to NOT ALLOW an explicitly declared connection to the insecure resource (accepting the expired certificate) as a primary action- and ignore/silence the warning for THAT specific connection- as a secondary, optional action. If, in order to ignore the warning, one would be required to ignore ALL WARNINGS (or all of that type e.g.: all suspicious connections via tcp/443), then I would definitely NOT set to ignore warnings in that case. The bottom line here is that Microsoft has decided that it does not need to renew an expired certificate- that, in itself, should tell the user enough information such that there isn't the need to explicitly ALLOW the connection through: if they were replacing whatever content/service was hosted there with something relevant to the user, then they would either secure it with a certificate (for activity sensitive enough to require it) or they would change the URL such that the user experience would not suffer such an annoyance. Microsoft's inaction, in this case, is all we need to know. Personally, I also receive this warning (via Bitdefender); however, I will not allow the connection simply to not receive the warning in the logs.

    One may apply the same logic for blocked connections from any other application logs, in a likewise fashion.

    Edit: Does simply ACCEPT'ing the expired certificate mean that one has suffered an exploit? No. However, any user that DOES accept an expired certificate for that URL has OPENED AN AVENUE OF ATTACK, which would from that point in time forward, make it POSSIBLE to exploit some other vulnerability from that URL on a machine that has accepted it.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-03-11T23:47:49+00:00

    Hi there,

    What version of Windows do you run ? What Edge version do you use ?

    Update to the new Chromium-based EDGE browser ( which is way better than the old Edge ). If not, use Firefox......

    Microsoft has its hands full with Windows Updates problems and this is an insignificant, harmless problem. They won't fix it because they are pushing people to the new Chrome-based EDGE................. so update ! 

    Use this link               https://www.microsoft.com/en-us/edge

    Ever since I updated to the new EDGE, on January 16th 2020, I have never had this problem with my BITDEFENDER TOTAL.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-03-11T23:30:51+00:00

    why haven't we gotten a good answer to this? I'm getting the same stupid error, every time. And why is edge trying to go to a site that I don't ask it to go to..?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2020-02-27T03:34:50+00:00

    Hello Tanya_T,

    thank you for providing this question.

    I am a seasoned Windows expert with almost a decade in usage and support experience and hope to resolve your problems quickly.

    I will need some context to answer this.

    Where did you encounter this name?

    It could be a software library path since it has points inbetween.

    If this solved your problem i am very happy if you would provide feedback and mark this as solved.

    If this didn't solve your problem or you need further assistance please answer in this thread and i would be happy to help.

    kind regards

    F. Grobusch

    I have been working in R&D since 1968 for a large Telecommunications Company as an Electronics Engineer for 10 years, then as Special Services Computer Communications manager for Special Sevices Network Design and then as Telecom Canada representative on up to seven CSA technical committees, many CCITT and ISO committees as well as Canadian liaison to USA ANSI committees. I have continued keeping up with computers, computer communication networks and end-to-end security for the last 26 years since retiring. I understand the use of certificates, how they expire and how my Bitdefender Total Network Security blocks possible hackers trying to find open ports to your system, or even your own system using these certificates.

    Yes, these are real invalid certificates and show that your security system is working.

    Was this answer helpful?

    0 comments No comments