Microsoft Edge is making Suspicious Connection?

Anonymous
2023-11-02T09:18:58+00:00

is Microsoft is making suspicious connection to this URL deff.nelreports.net/api/report?

Also let us know which data is being sent to this URL & When?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-11-15T15:40:03+00:00

*.nelreports.net is a Microsoft domain. Several certificates used on the subdomains of this domain expired last week.

There is no security impact or end-user-impact of the certificate expiration -- Basically, the browser will be unable to submit Network Error Logging reports until the certificate is corrected. Network Error Logging is a HTML5 feature to allow site owners to discover network connectivity problems. https://developer.mozilla.org/en-US/docs/Web/HTTP/Network\_Error\_Logging

Your security software is just announcing "Hey, this certificate is bad", a fact that the browser already was determining on its own, and to which it responds by not connecting to the server in question. The security software provides a redundant warning -- the browser will not use connections with expired or invalid certificates.

The subdomain names are random strings of characters with no particular meaning.

The relevant team has been notified about the certificate expiration and will correct the issue.

Was this answer helpful?

8 people found this answer helpful.
0 comments No comments

51 additional answers

Sort by: Newest
  1. Rob Koch 26,170 Reputation points Volunteer Moderator
    2023-11-15T05:59:34+00:00

    Stephen,

    I didn't know what nelreports.net was about until I started investigating myself, while everyone else in these and the other threads I've seen here are so focused on the {obviously} expired certificate that Bitdefender is detecting that they've ignored completely what it might actually be used for.

    Since you don't know how threads here work, scroll to the bottom of the page and you'll find a listing of the other pages in the thread, preceded by the word 'Previous', with the current page number highlighted.

    Simply click whichever of these you'd like to move through the thread, in this case press page number 2 and scroll down a few posts to see my previous post where I initially described my first guesses, then came back and added and 'EDIT' where I describe in more detail what I found out about NELReporting, its purpose and why I wouldn't be worried about whether this particular certificate was expired or not.

    No, it wasn't immediately obvious what nelreports.net was for, nor any of these other details, but since I've been dealing with such issues myself both professionally and personally for decades, it simply takes a little time with search and other online tools to learn anything you want, since the web is inherently a map to everything it contains that any knowledgeable person can follow.

    My post is a bit rambling, but I refer to keep the original musings as a record rather than remove them, since otherwise any later comments might also lose context.

    Once you've read that you're free to come back and make your case for why you still feel this expired certificate situation is urgent, but as I stated it's only made so by a detection that virtually no other security app chooses to make, while even though it's expired, nothing appears to be failing for anyone else not using Bitdefender with MSEdge.

    As for Bitdefender itself, its reputation for a 'feature' that added their own local certificate to allow Man-in-the-Middle operation to monitor the browser(s) SSL secure traffic, effectively removing all security for anything transmitted as a side effect, is well known to all security professionals and most long-term helpers in any security related forum as well. Though as I understand it this feature was at least removed as a default, I'd never trust an app that did this without warning.

    Here's one Reddit thread that discussed this back when it was in effect, though the one I saw at the time was much larger and more involved, but you'll get the gist from these few posts.

    Bitdefender Total Security hijacking browser's SSL connections - Acceptable practice? : r/AskNetsec

    I simply see no need for any 3rd-party security with Windows Defender included free with Windows, that is unless you've got some sort of specialized need that this relatively simple to use product doesn't provide. For some reason people get religious (read; Mythology) about their security apps, though in many cases that trust is not well placed.

    Rob

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-11-15T01:49:52+00:00

    If I hadn't happened to buy Bitdefender (instead of Norton, for example) then I wouldn't have known there was a problem with nelreports.net in all its permutations. If its certificate is fixed, will it do its wicked spyware deeds behind the scenes without detection? My guess is that another area of Bitdefender will block it. If that is not the case, then what will? Suppose it is renamed to nelreports1.net instead and given a good certificate. It would have passed the certificate check in Bitdefender, but when it started spying or doing whatever it does for illicit profits (like redirecting the browser to other e-commerce sites), surely Bitdefender would come to the rescue.

    I'm willing to occasionally click on Bitdefender Notifications, click "Mark all as read" and be done with it. This issue is jarring because it makes one wonder what nasty mischief is going on "under the hood" in Windows 11 and whether Bitdefender is blocking it all. Until there's malware software rated better, I'll stick with Bitdefender. Norton didn't even warn me about nelreports.net! It's a major pain, so I switched to Bitdefender, and that appears to have been a lucky change.

    I believe in overkill on security and wish I could install ALL the most highly rated malware programs. (I have cameras and sensors hidden all over the place in and around my house.) I left Norton turned on, and there are no collisions thus far with Bitdefender, so that's probably enough.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-11-14T23:44:46+00:00

    Read the entire thread Steven & Phober, there's a lot more known about this Microsoft MSN support website than you realize, so it really doesn't matter from a security sense that the certificate isn't up to date, since all of the sites involved are within Microsoft's control.

    That's not saying it's a false positive, but in truth, Bitdefender displaying this alert in this case is simply annoying the user and doing nothing to truly 'protect' you.

    In fact, from what I've seen, the simplest way to remove the problem is to simply turn off the MSN Newsfeed on the default New Tab settings in Microsoft Edge, since that's apparently where the article pages are that are calling these particular error reporting pages with the expired certificate. In other words, if the MSN News pages don't display, the errors also shouldn't occur, though I don't have Bitdefender to test and would never want it installed on my own devices.

    I've personally disabled the MSN Newsfeed and other default Microsoft start pages over 2 decades ago, since I prefer a simple About: Blank web page with no content as my own initial display, so I'd never see this issue in any case. I don't believe in vendor provided pages and instead prefer to choose my own, which provides true security and privacy.

    Rob

    Rob Koch, evidently you are far more knowledgeable than I about Windows, MSEdge and MSN. I couldn't and didn't presume that the suspect ????.nelreports.net sites would automatically be Microsoft sites.

    I followed the Microsoft help link but only received one screen. I don't recall any obvious indication that there were historical discussions that I could review, and I doubt whether I would have understood any jargon if I had found them.

    I'm also disheartened by your condemnation of Bitdefender without explanations or suggested alternatives. That strikes me as unprofessional.

    Stephen Cooper

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Rob Koch 26,170 Reputation points Volunteer Moderator
    2023-11-14T19:04:12+00:00

    Read the entire thread Steven & Phober, there's a lot more known about this Microsoft MSN support website than you realize, so it really doesn't matter from a security sense that the certificate isn't up to date, since all of the sites involved are within Microsoft's control.

    That's not saying it's a false positive, but in truth, Bitdefender displaying this alert in this case is simply annoying the user and doing nothing to truly 'protect' you.

    In fact, from what I've seen, the simplest way to remove the problem is to simply turn off the MSN Newsfeed on the default New Tab settings in Microsoft Edge, since that's apparently where the article pages are that are calling these particular error reporting pages with the expired certificate. In other words, if the MSN News pages don't display, the errors also shouldn't occur, though I don't have Bitdefender to test and would never want it installed on my own devices.

    I've personally disabled the MSN Newsfeed and other default Microsoft start pages over 2 decades ago, since I prefer a simple About: Blank web page with no content as my own initial display, so I'd never see this issue in any case. I don't believe in vendor provided pages and instead prefer to choose my own, which provides true security and privacy.

    Rob

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments