frostengine is correct.
Hackers now install bots on your computer that use port 80 (which is never blocked on a computer you browse the internet with), to connect outbound to a site that lists commands for the bot to perform. No firewall can block this activity because its a pull model, not a push model.
Bots are on a schedule, and read their command list at X time several times a day.
The command will often be, "wait until next cmd"
But the hacker now knows how many bots he has managed to install on other machines as they check in to see what their next command is.
Once he has infected enough computers, and has enough bots reporting in, he then posts the command to the secret website "buy BLAH @ 12:30pm", the bots log in and get their command and wait until that moment.
At 12:28 the hackers buy tons of BLAH, then the bots fire and push the price up and he sells.
Then the loop continues until he's blown all the accounts out
No security device will save you from this. As long as your TWS is logged in and connected ***AFTER*** you have entered the security code, the bots can control it and send market orders.
The bots dont connect to the hackers machine, giving up his IP address. They typically use a 3rd party chat channel or something similar and encode their commands.
In any case, it sucks the official message did not have the opt-out in it. Hopefully, it really is only for advisors.
If they try to stuff this down my throat, as I said before ill take thousands of dollars worth of commissions each month to genesis and ill trash IB everywhere I go for being stupid. I really dont want to have to re-code my execution interfaces, but will if they do this.
They will lose millions in ATS trader profit if they do this.