Quote from Bob111:
i raise this question before, but no respond from IB. once again-what about in case of short disconnection? or if you or someone else log in your account in TWS from different machine and you got that famous pink grid? (i'm personally use it all the time to create disconnection while working on handler of such event)-do you have to use device again?
Thank you!
Quote from IB Salvatore:
Short disconnects - No authentication
Pink Screens - No Authentication
Competing log ins that result in a log out- New Authentication
Quote from SideShowBob:
Sal...I'd question that. I agree a short disconnection should not cause a new challenge.
But someone logging into the same account from a completely different IP address...that seems like a big red flag.
If both machines are behind the same router they'd both appear to be the same IP address to the IB servers (I think so anyway), so you'd probably be safe ... but if they were from two different locations on the internet I'd think you'd want to get a challenge (or at least a popup saying that's why you got a pink out and if you weren't doing this on purpose you'd know someone had somehow hacked your account).
Thoughts?
Quote from Businessman:
I would have prefered the time based tokens.
With a bit of coding and state maintenance at IBs end you could ensure that time based tokens could be played only once.
It seems IB went for an approach that wouldnt require too much coding, the current implementation seems to be a stand alone module. However they are going to have to come up with something more integrated into TWS to get over the pink outs not requiring a new challenge issue.
Quote from SideShowBob:
Sal...I'd question that. I agree a short disconnection should not cause a new challenge.
But someone logging into the same account from a completely different IP address...that seems like a big red flag.
If both machines are behind the same router they'd both appear to be the same IP address to the IB servers (I think so anyway), so you'd probably be safe ... but if they were from two different locations on the internet I'd think you'd want to get a challenge (or at least a popup saying that's why you got a pink out and if you weren't doing this on purpose you'd know someone had somehow hacked your account).
Thoughts?