Microsoft Edge is making Suspicious Connection?

Anonymous
2023-11-02T09:18:58+00:00

is Microsoft is making suspicious connection to this URL deff.nelreports.net/api/report?

Also let us know which data is being sent to this URL & When?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-11-15T15:40:03+00:00

*.nelreports.net is a Microsoft domain. Several certificates used on the subdomains of this domain expired last week.

There is no security impact or end-user-impact of the certificate expiration -- Basically, the browser will be unable to submit Network Error Logging reports until the certificate is corrected. Network Error Logging is a HTML5 feature to allow site owners to discover network connectivity problems. https://developer.mozilla.org/en-US/docs/Web/HTTP/Network\_Error\_Logging

Your security software is just announcing "Hey, this certificate is bad", a fact that the browser already was determining on its own, and to which it responds by not connecting to the server in question. The security software provides a redundant warning -- the browser will not use connections with expired or invalid certificates.

The subdomain names are random strings of characters with no particular meaning.

The relevant team has been notified about the certificate expiration and will correct the issue.

Was this answer helpful?

8 people found this answer helpful.
0 comments No comments

51 additional answers

Sort by: Most helpful
  1. Anonymous
    2023-11-15T16:09:38+00:00

    Eric, thanks for replying in laymen's terms.

    Being a (Civil*) Engineer, I tend to think of causes and effects. Putting your and others' replies together, I understand that MSEdge is requesting data or actions through *.nelreports.net but being blocked by its obsolete SSL codes, triggering faults that my BitDefender software is logging.

    My main concern was that I could not tell whether *.nelreports.net housed malware that might break through this computer's defences. In that respect, Bitdefender's reports were unhelpful.

    *That doesn't mean I'm always polite. I'm simply not a Military Engineer.

    Stephen Cooper

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-11-15T12:56:59+00:00

    Eugene, thank-you for endorsing my concerns.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-11-15T08:28:03+00:00

    "

    To see how Microsoft Edge or any other browser handles these and other types of SSL (Certificate) errors, the following page has the most common of these displayed in red lettering immediately below the 'Certificate' title in the left-hand column.

    badssl.com

    When Edge displays one of these certificate errors, there's a button titled 'Advanced' immediately below the error message on the lower left-hand side of the page. Pressing this provides a more complete and somewhat more readable description of what the particular error message actually means.

    "

    So, trusting the site just had an expired certificate (& that Microsoft has Edge go there surreptitiously), I tried to go there directly using Edge & was stopped with the following message...

    Image

    I won't click to continue. Hopefully, Edge's surreptitious visit also does not click it. I don't have BitDefender. I just use Defender with SmartScreen turned on.

    Was this answer helpful?

    0 comments No comments
  4. Rob Koch 26,170 Reputation points Volunteer Moderator
    2023-11-15T05:59:34+00:00

    Stephen,

    I didn't know what nelreports.net was about until I started investigating myself, while everyone else in these and the other threads I've seen here are so focused on the {obviously} expired certificate that Bitdefender is detecting that they've ignored completely what it might actually be used for.

    Since you don't know how threads here work, scroll to the bottom of the page and you'll find a listing of the other pages in the thread, preceded by the word 'Previous', with the current page number highlighted.

    Simply click whichever of these you'd like to move through the thread, in this case press page number 2 and scroll down a few posts to see my previous post where I initially described my first guesses, then came back and added and 'EDIT' where I describe in more detail what I found out about NELReporting, its purpose and why I wouldn't be worried about whether this particular certificate was expired or not.

    No, it wasn't immediately obvious what nelreports.net was for, nor any of these other details, but since I've been dealing with such issues myself both professionally and personally for decades, it simply takes a little time with search and other online tools to learn anything you want, since the web is inherently a map to everything it contains that any knowledgeable person can follow.

    My post is a bit rambling, but I refer to keep the original musings as a record rather than remove them, since otherwise any later comments might also lose context.

    Once you've read that you're free to come back and make your case for why you still feel this expired certificate situation is urgent, but as I stated it's only made so by a detection that virtually no other security app chooses to make, while even though it's expired, nothing appears to be failing for anyone else not using Bitdefender with MSEdge.

    As for Bitdefender itself, its reputation for a 'feature' that added their own local certificate to allow Man-in-the-Middle operation to monitor the browser(s) SSL secure traffic, effectively removing all security for anything transmitted as a side effect, is well known to all security professionals and most long-term helpers in any security related forum as well. Though as I understand it this feature was at least removed as a default, I'd never trust an app that did this without warning.

    Here's one Reddit thread that discussed this back when it was in effect, though the one I saw at the time was much larger and more involved, but you'll get the gist from these few posts.

    Bitdefender Total Security hijacking browser's SSL connections - Acceptable practice? : r/AskNetsec

    I simply see no need for any 3rd-party security with Windows Defender included free with Windows, that is unless you've got some sort of specialized need that this relatively simple to use product doesn't provide. For some reason people get religious (read; Mythology) about their security apps, though in many cases that trust is not well placed.

    Rob

    Was this answer helpful?

    0 comments No comments