goto fail; // Apple SSL bug test site

This is a test site to check whether your browser verifies the signature on the ServerKeyExchange SSL/TLS message.

Please see agl's writeup for a full description of the bug.

Apple has released official iOS updates that resolve this issue.

A third party patch for OS X, which I have not reviewed and cannot vouch for, is available from i0n1c.

Please wait while we test your browser...

This site works by using javascript to inject a hidden image with event hooks to show the appropriate message depending on whether the image loads successfully. The image is hosted on a web server which has been modified to make its ServerKeyExchange message signatures invalid. The invalid signature will cause the connection to abort when the signature is checked, provided that the signature is actually verified.

For more browser SSL/TLS testing check out How's my SSL?

If you'd like to donate, feel free to send bitcoin to 19xUQVwyc5DDo1uoN8dXA8tCEfXCrkRyir or give something to EFF. Fan mail (or hate mail) to gotofail@gotofail.com some design help with the site would be really nice.