Originally posted by easyrider
If they got your password they would then have to change your banking instructions which would have to be confirmed by an email to you which you would see in time to notify IB that something was amiss unless they could intercept and delete your confirmation email before it got to you. Is this possible?
Good point. But it does not make me feel any better

Say I have your account number and password: I have access to your account now. What prevents me from changing the email address that IB is going to use from now on? Nothing. And you'll never know that someone else logged in as you until it's too late. Even if I could not change the email address (but my take on it is that I could, I don't see why not), then once in possession of your password (remember, I already have your login name) I could log in as you, download TWS and trade your account. How would you like that? Lots of the so-called hackers are out there simply out to create havoc and mischief. Maybe they can't transfer the money to themselves and if they can they will, but if they can't they'll be quite happy to mess up your life. And how will you get compensation from IB? How will you prove that it was not you, but someone else that accessed your account?
Also, think identity theft here. Even if I cannot do anything to your account , I know your name, your full address, and how much you got into your IB account. You think it's not enough? It's a good start, let me tell you.
And something else... Do you have a large amount in your account? Like, say $1 million ++. You got children? With your name and address I could find out, you know. Now, how would you like some dirtbag out there to be privy to this information?
Well, there is only a password between you and all that crap now. Do you use an easy to remember password? Then maybe it's easy to crack too. Capturing the email info out of the Internet traffic, that's easy for sure.
Bottom line is that IB has a huge obvious security hole here, but it's easy to fix. I just hope that they do so before some hackers get onto it.
ElvisOnMargin