Hi everyone, I’m a security researcher. I just came across the Canton network and see how it could be really valuable. I’m diving into its ecosystem.
Currently, I have been learning the DAML training program. I have passed the fundamental certification and am just going through the dev ones.
So I have a question: Is there currently, or is there planned to be, any certification for security researchers? Right now, I only see certifications for developers.
I am not aware of such plans. There are a variety of blogs from various security audits firms that talk to the potential areas of concern with multi-party Daml models.
What might you want from such a certification / course?
In the security space, we want to show others that we have experience with Canton and DAML. We need a certain certification so that we can be hired by the project.
For me, I already have the certification and have done a few audit for DAML, but I just want to make sure if there is an official partner program or something similar.
There’s no security-specific certification, though various security topics - external signing, compliance & enterprise design, Daml’s authorization model, etc - are peppered across modules of the existing certification curriculum.
@Jes I’d love to hear more of your thoughts as they arise and start to think-out-loud about the possible interplay with audits.
Hi, @Colin thanks for the feedback. I think for Security Researchers, a security certification could be a really valuable addition.
Having already passed both the Developer and Fundamentals certifications, it seems clear to me that a solid understanding of the DAML and underlying mechanisms is essential for auditing DAML contracts effectively. Without that foundation, it is difficult to identify deeper security issues beyond business-logic mistakes.
It might therefore be worth introducing a dedicated security course or certification, covering security best practices for both auditors and developers. Combining different pieces into a dedicated track would allow for a much deeper dive into the actual security model.
I guess it remains to be checked how many people are really wanting to learn this. But for me, I’m certainly one of them.