Microsoft Edge is making Suspicious Connection?

Anonymous
2023-11-02T09:18:58+00:00

is Microsoft is making suspicious connection to this URL deff.nelreports.net/api/report?

Also let us know which data is being sent to this URL & When?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-11-15T15:40:03+00:00

*.nelreports.net is a Microsoft domain. Several certificates used on the subdomains of this domain expired last week.

There is no security impact or end-user-impact of the certificate expiration -- Basically, the browser will be unable to submit Network Error Logging reports until the certificate is corrected. Network Error Logging is a HTML5 feature to allow site owners to discover network connectivity problems. https://developer.mozilla.org/en-US/docs/Web/HTTP/Network\_Error\_Logging

Your security software is just announcing "Hey, this certificate is bad", a fact that the browser already was determining on its own, and to which it responds by not connecting to the server in question. The security software provides a redundant warning -- the browser will not use connections with expired or invalid certificates.

The subdomain names are random strings of characters with no particular meaning.

The relevant team has been notified about the certificate expiration and will correct the issue.

Was this answer helpful?

8 people found this answer helpful.
0 comments No comments

51 additional answers

Sort by: Oldest
  1. Anonymous
    2023-11-15T09:30:28+00:00

    Quoting a Reddit post from 9 years ago as a source of truth about a product is not a good idea. And it should be obvious why it's not.

    As advising people to trust a website because it is under Microsoft control or anyone else control when their certificates are expired is dangerous.

    Certificates are a key part of the security implementation and one of their functions is to Certify the website you try to reach is legit.

    Discarding this warning is like sending money to someone without checking his identity. 'Look he has 2 legs, 2 arms and a head, pretty sure it's him!'

    Just, no.

    People at Microsoft had probably warnings WEEKS before the expiration of those certificates and they did nothing.

    Problem is not with Defender, stop shooting the messenger.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-11-15T12:56:59+00:00

    Eugene, thank-you for endorsing my concerns.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-11-15T16:09:38+00:00

    Eric, thanks for replying in laymen's terms.

    Being a (Civil*) Engineer, I tend to think of causes and effects. Putting your and others' replies together, I understand that MSEdge is requesting data or actions through *.nelreports.net but being blocked by its obsolete SSL codes, triggering faults that my BitDefender software is logging.

    My main concern was that I could not tell whether *.nelreports.net housed malware that might break through this computer's defences. In that respect, Bitdefender's reports were unhelpful.

    *That doesn't mean I'm always polite. I'm simply not a Military Engineer.

    Stephen Cooper

    Was this answer helpful?

    0 comments No comments
  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more