Protecting Exchange Credentials with Local Key Files
Summary
The guide explains how FMZ handles sensitive account details and strategy parameters. It says these values are encrypted in the browser and stored as encrypted data, with decryption available on the user's private device. It also cautions against exposing confidential information inside strategy code, parameters, or descriptions shared with others.
For RSA-based exchange authentication, the guide describes storing the private key as a local text file on the device running the FMZ host, then entering its file path in the exchange configuration so the host loads it when the strategy uses that exchange. It also notes that changing the FMZ account password invalidates exchange configurations: users must re-enter exchange credentials and restart hosts using the updated password. These are platform-specific handling steps, not an independent security assessment; the document provides no threat model or comparative evidence about encryption strength.
Key ideas
- FMZ encrypts sensitive account information and strategy parameters in the browser before storing them.
- An RSA private key can be kept in a local file and loaded by the host through a file path in the exchange settings.
- Confidential information embedded in shared strategy code or descriptions can be exposed.
- Changing the FMZ account password invalidates exchange configurations, which must then be re-entered.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.