Microsoft Edge is making Suspicious Connection?

Anonymous
2023-11-02T09:18:58+00:00

is Microsoft is making suspicious connection to this URL deff.nelreports.net/api/report?

Also let us know which data is being sent to this URL & When?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-11-15T15:40:03+00:00

*.nelreports.net is a Microsoft domain. Several certificates used on the subdomains of this domain expired last week.

There is no security impact or end-user-impact of the certificate expiration -- Basically, the browser will be unable to submit Network Error Logging reports until the certificate is corrected. Network Error Logging is a HTML5 feature to allow site owners to discover network connectivity problems. https://developer.mozilla.org/en-US/docs/Web/HTTP/Network\_Error\_Logging

Your security software is just announcing "Hey, this certificate is bad", a fact that the browser already was determining on its own, and to which it responds by not connecting to the server in question. The security software provides a redundant warning -- the browser will not use connections with expired or invalid certificates.

The subdomain names are random strings of characters with no particular meaning.

The relevant team has been notified about the certificate expiration and will correct the issue.

Was this answer helpful?

8 people found this answer helpful.
0 comments No comments

51 additional answers

Sort by: Oldest
  1. Rob Koch 26,170 Reputation points Volunteer Moderator
    2023-11-11T04:21:22+00:00

    Based on the Technical Contact Name of "MSN Hostmaster" in that Whois Registration record that _AW_ referenced, I suspect this was a legacy service being used by Microsoft's MSN group for trouble-shooting browser connectivity issues. Likely it's a service they've dropped that is referenced internally by the browser itself but doesn't create an error message because it operates in the background, while the unrelated security feature in Bitdefender is detecting it due to the certificate issue.

    The reason I say this is that there have apparently been previous instances of reporting by Bitdefender of similar issues with MSEdge and other services that were either dropped or malfunctioning, so it's not new, just a new site/service triggering this Bitdefender "protection", while no one else is even aware it's happening.

    Here's an old thread about the EBooks reading feature that was triggering this error in 2019:

    MicrosoftEdge.exe Suspicious Connection? - Microsoft Community

    Here's another back in 2021 where a few were having issues with what appears to be the Store's extensions database service, which based on the posts was likely transiently malfunctioning in some way at least for these users.

    Microsoft Edge - Bitdefender Blocking Suspicious Connection On Load - Microsoft Q&A

    I think a saw a couple others, but I'll stop there and let you look for those yourself if you wish.

    Based on all of this and the history I found of these relatively useless Bitdefender detections in general, I'd at least set an exception for this current error likely relating to MSN and if it was me, I'd turn off what's obviously not a useful security feature in todays' world, since MSEdge itself warns quite effectively when websites I browse normally don't contain a valid certificate. In fact, Edge has become rather aggressive about making me aware of websites that aren't properly SSL secured by making them difficult to access.

    Rob

    < EDIT > Minor wording or spelling errors fixed. Following section added.

    To see how Microsoft Edge or any other browser handles these and other types of SSL (Certificate) errors, the following page has the most common of these displayed in red lettering immediately below the 'Certificate' title in the left-hand column.

    badssl.com

    When Edge displays one of these certificate errors, there's a button titled 'Advanced' immediately below the error message on the lower left-hand side of the page. Pressing this provides a more complete and somewhat more readable description of what the particular error message actually means.

    To further clarify what I meant in my first paragraph by "trouble-shooting browser connectivity issues", see the following documents that describe the W3C's Network Error Logging (NEL) first briefly and then in excruciating detail. Note that I included the first document from NELReports,com due to it's simple description of the purpose, while the others provide technical reference both from the Mozilla (MDN) developer network and the W3C itself relating to NEL.

    Network Error Logging - NEL Reports

    Network Error Logging - HTTP | MDN

    Network Error Logging - W3C

    A more focused description of what I believe happened is that as another thread here discovered, the certificate related to this domain had expired the previous day, which is obviously why the Bitdefender detection is occurring. However, whether this is truly an issue or not depends upon whether Microsoft MSN intends to continue using the NEL reporting service or not, since another way to eventually 'fix' the issue is to simply remove the code which is calling this, whether that's internal to MS Edge or contained on various web pages displayed by the MSN News Feed some in that other thread some feel might be involved.

    In either case, leaving the detection in place and complaining about it will change nothing, since it's a weekend and likely no one with the ability to update the certificate is in the office, so the obvious fix is to at least temporarily exclude the site[s] creating the issues for you personally. If MSN is planning to remove the NEL calls from their pages and no longer support it, then it may never truly be fixed and only disappear over time as the pages involved are either updated or exit the site by attrition.

    No one here knows the answer to that and until we either get confirmation from someone at MSN, the certificate is renewed, or the problem disappears for another reason like code modification, we have no way of knowing. Since the site(s) and code involved are all within Microsoft's control, it doesn't really matter that this error is occurring, so leaving the detection intact and letting it annoy you is simply foolish, so turn it off or exclude it until you hear otherwise.

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-11-11T05:11:04+00:00

    it happend to me now deff.nelre.net like you said please help us

    Was this answer helpful?

    0 comments No comments
  3. _AW_ 69,496 Reputation points Volunteer Moderator
    2023-11-11T05:25:20+00:00

    Report the potential false positive detection to Bitdefender:

    https://www.bitdefender.com.au/consumer/support/answer/88562/

    Then add the site to Bitdefender's exclusions:

    How to stop Bitdefender from blocking a safe website or an online app

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-11-11T05:30:07+00:00

    This is interesting as I am having the same issue. I also utilize Bitdefender. However, when I used Bitdefender VPN for the free time of about 200MB they give I don't get that. In a previous message could this be something Bitdefender should look into....or is anyone in this thread NOT using Bitdefender.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments