Quote from kiwi_trader:
IB encrypt the logon sequence so the highest risk is probably on your local PC. With all passwords its wise to change them from time to time and to ensure that they are not easily read over ones shoulder (use some odd characters in it).
I used to change my passwords from time to time but since there are so many passwords nowadays to handle, it would be a headache to keep track of all your new passwords. I have kept some of my passwords for a while without changing and have not seen anything happen. My question is "is it safer to keep the same password than changing it from time to time?" My thinking is that if a hacker knew your password, he would do something on that info in seconds. It is the process of changing password that somehow exposes your password to a hacker than if you keeps your same old password diligently with all prevention of virus, keylogger... on your computer.