# Some questions and concerns

**URL:** <https://forum.dfinity.org/t/some-questions-and-concerns/6836>\
**Category:** Developers\
**Created:** [August 31, 2021, 2:19pm UTC](https://forum.dfinity.org/t/some-questions-and-concerns/6836 "2021-08-31T14:19:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ccyanxyz](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/ccyanxyz/32/1025_2.png) [@ccyanxyz](https://forum.dfinity.org/u/ccyanxyz)\
**Post date:** [August 31, 2021, 2:19pm UTC](https://forum.dfinity.org/t/some-questions-and-concerns/6836/1 "2021-08-31T14:19:56Z")

</div>

Hi there, I’m a developer from DFinance and we have some questions:

1. Recently, the [pjljw](https://dashboard.internetcomputer.org/subnet/pjljw-kztyl-46ud4-ofrj6-nzkhm-3n4nt-wi3jt-ypmav-ijqkt-gjf66-uae) subnet is unstable. Is there any way to migrate canisters from 1 subnet to another subnet? If so, how to migrate the data within the canisters?

2. Is there any suggestion on how to backup the canister data? If the subnet is down(unlikely) or canister hacked(very possible when it comes to financial applications), we need to restore the state back to the original state to eliminate the effect of hacking, so I think maybe we need a way to backup canister data.

3. Is there any security audit services for the Internet Computer ecosystem now? Especially for Motoko. Security is the most important thing for a new ecosystem, especially when it comes to financial applications. TheDAO hack could have killed Ethereum, we don’t want that kind of thing happen to the Internet Computer.

---

<div class="post-metadata">

**Author:** ![nomeata](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/nomeata/32/733_2.png) [@nomeata](https://forum.dfinity.org/u/nomeata)\
**Post date:** [August 31, 2021, 6:20pm UTC](https://forum.dfinity.org/t/some-questions-and-concerns/6836/2 "2021-08-31T18:20:03Z")

</div>

My non-authorative take on that:

1. Canister migration is not implemented, but at least it was taken into consideration. In particular the mapping from canister id (which you surely want to keep) to cansiter is flexible enough to change it for some or all canisters.

2. For now: implement backups in application logic (a query method that checks that the caller is you). I predict we’ll get the ability to inspect the full cansiter state, which is also important for debugging, including suitable authentication, but I haven’t seen it on any roadmap yet, so don’t expect it to be done before your need backups.

3. I am not aware of a security audit of Motoko.

---

<div class="post-metadata">

**Author:** ![ccyanxyz](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/ccyanxyz/32/1025_2.png) [@ccyanxyz](https://forum.dfinity.org/u/ccyanxyz)\
**Post date:** [September 1, 2021, 12:47pm UTC](https://forum.dfinity.org/t/some-questions-and-concerns/6836/3 "2021-09-01T12:47:49Z")

</div>

Thanks for the reply 🙂
