Microsoft Edge is making Suspicious Connection?

Anonymous
2023-11-02T09:18:58+00:00

is Microsoft is making suspicious connection to this URL deff.nelreports.net/api/report?

Also let us know which data is being sent to this URL & When?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-11-15T15:40:03+00:00

*.nelreports.net is a Microsoft domain. Several certificates used on the subdomains of this domain expired last week.

There is no security impact or end-user-impact of the certificate expiration -- Basically, the browser will be unable to submit Network Error Logging reports until the certificate is corrected. Network Error Logging is a HTML5 feature to allow site owners to discover network connectivity problems. https://developer.mozilla.org/en-US/docs/Web/HTTP/Network\_Error\_Logging

Your security software is just announcing "Hey, this certificate is bad", a fact that the browser already was determining on its own, and to which it responds by not connecting to the server in question. The security software provides a redundant warning -- the browser will not use connections with expired or invalid certificates.

The subdomain names are random strings of characters with no particular meaning.

The relevant team has been notified about the certificate expiration and will correct the issue.

Was this answer helpful?

8 people found this answer helpful.
0 comments No comments

51 additional answers

Sort by: Most helpful
  1. Anonymous
    2023-11-15T09:30:28+00:00

    Quoting a Reddit post from 9 years ago as a source of truth about a product is not a good idea. And it should be obvious why it's not.

    As advising people to trust a website because it is under Microsoft control or anyone else control when their certificates are expired is dangerous.

    Certificates are a key part of the security implementation and one of their functions is to Certify the website you try to reach is legit.

    Discarding this warning is like sending money to someone without checking his identity. 'Look he has 2 legs, 2 arms and a head, pretty sure it's him!'

    Just, no.

    People at Microsoft had probably warnings WEEKS before the expiration of those certificates and they did nothing.

    Problem is not with Defender, stop shooting the messenger.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-11-14T23:44:46+00:00

    Read the entire thread Steven & Phober, there's a lot more known about this Microsoft MSN support website than you realize, so it really doesn't matter from a security sense that the certificate isn't up to date, since all of the sites involved are within Microsoft's control.

    That's not saying it's a false positive, but in truth, Bitdefender displaying this alert in this case is simply annoying the user and doing nothing to truly 'protect' you.

    In fact, from what I've seen, the simplest way to remove the problem is to simply turn off the MSN Newsfeed on the default New Tab settings in Microsoft Edge, since that's apparently where the article pages are that are calling these particular error reporting pages with the expired certificate. In other words, if the MSN News pages don't display, the errors also shouldn't occur, though I don't have Bitdefender to test and would never want it installed on my own devices.

    I've personally disabled the MSN Newsfeed and other default Microsoft start pages over 2 decades ago, since I prefer a simple About: Blank web page with no content as my own initial display, so I'd never see this issue in any case. I don't believe in vendor provided pages and instead prefer to choose my own, which provides true security and privacy.

    Rob

    Rob Koch, evidently you are far more knowledgeable than I about Windows, MSEdge and MSN. I couldn't and didn't presume that the suspect ????.nelreports.net sites would automatically be Microsoft sites.

    I followed the Microsoft help link but only received one screen. I don't recall any obvious indication that there were historical discussions that I could review, and I doubt whether I would have understood any jargon if I had found them.

    I'm also disheartened by your condemnation of Bitdefender without explanations or suggested alternatives. That strikes me as unprofessional.

    Stephen Cooper

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2023-11-14T12:54:26+00:00

    It is not false positive! The site does not have a valid certificate, so it could be redirected to a hacker site.

    Most probably it is not redirected anywhere, only the certificate is invalid as expired, but anyhow it should not be reported as false positive, the cert must be fixed.

    NO! If "deff.nelreports.net" and/or "bzib.nelreports.net" is/are malicious, "fixing" the certificate is completely WRONG. It should be inspected and deleted if necessary. That's a job for Microsoft.

    I have to trust Bitdefender's certificate check and refusal on the ground of invalidity.

    I have never seen either "deff.nelreports.net" or "bzib.nelreports.net" on this or any of my other computers so I presume it is malicious. I cannot determine whether Bitdefender's warning messages arise from access attempts by that website to the Edge software on this computer or a call from Edge to that website. I presume the former but do not know how to prevent its future success and damage if it obtains a valid certificate.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-11-13T08:05:16+00:00

    These are the reports I get using EdgeDev

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments