newpump said:I wonder if elitefitness has ever has a network, host and application security assessment performed by a major (and reputable - not a small mom and pop shop) security provider? Would be nifty if they did a comprehensive check - and posted it in a secure location for paying people (platinum) to see (with the security sensitve areas blacked out maybe - IP addy's system names etc etc). They could also perform periodic scans after the initial scan and provide them as proof too - this would be a GREAT value add in my opinion.
Not plausible. Way too expensive for a thorough scan. Most security assessments (including those done by the majors) are nothing more than a nessus scan with a couple of custom scripts thrown in. A code audit is needed. Unfortunately it's way too cost prohibitive.