HOME FORUMS BROKERS SOFTWARE BOOKS CONTACT US
Elite Trader Your Account  •  Become a Member  •  Help  •  Search    
    Forums ›› Direct-Access Brokers ›› Retail Firms ›› IB TWS security token asked after disconnection  


Post A Reply
    Page 21 of 22:   « First Page   12  13  14  15  16  17  18  19  20   21  22  
dst
Interactive Brokers

Registered: Sep 2004
Posts: 129

 

08-09-12 09:32 PM

Seeing a challenge mid-session is not normal; whoever have a recent case - please execute Ctrl-Alt-H, upload the logs (put "Att: Dennis" in the notes) and PM me their user id, I will investigate this further (alternatively they can PM me and I'll reply with my IB email so we can take this conversation off ET board if they are not comfortable with exchanging some sensitive information here). Thank you.

__________________
Interactive Brokers
Follow Interactive Brokers on Facebook

    Edit/Delete Quote Complain
fullautotrading
 

Registered: Mar 2010
Posts: 593

 

08-09-12 09:55 PM


Quote from dst:

Seeing a challenge mid-session is not normal; whoever have a recent case - please execute Ctrl-Alt-H, upload the logs (put "Att: Dennis" in the notes) and PM me their user id, I will investigate this further (alternatively they can PM me and I'll reply with my IB email so we can take this conversation off ET board if they are not comfortable with exchanging some sensitive information here). Thank you.



What do you have to investigate ?

Just store credentials when logging in and, in case of disconnection just relog in * without rechallenging * . Once one has logged in, the challenge must not be done again, until he shuts down the program.

Is it so hard to just place a boolean flag in the client ?

Then you can do whatever you like server side (even struggling with the bug for the next century). We dont care about that.

    Edit/Delete Quote Complain
dst
Interactive Brokers

Registered: Sep 2004
Posts: 129

 

08-09-12 10:03 PM


Quote from fullautotrading:

What do you have to investigate ?

Just store credentials when logging in and, in case of disconnection just relog in * without rechallenging * . Once one has logged in, the challenge must not be done again, until he shuts down the program.



This is much more involved than "just storing credentials": we need to make sure you are who you say you are when you reconnect; I'm not going to explain in details the security algo used here, but think about this for a moment - if you are using dynamic second token device (that generates new token every few seconds) - what exactly it is we need to store and how will I differentiate you from the intruder next door who reconnects with the same ip and claims that he is you?

The logs will help me pinpoint why security algo did not work as expected.

__________________
Interactive Brokers
Follow Interactive Brokers on Facebook

    Edit/Delete Quote Complain
fullautotrading
 

Registered: Mar 2010
Posts: 593

 

08-09-12 10:11 PM


Quote from dst:

This is much more involved than "just storing credentials": we need to make sure you are who you say you are when you reconnect; I'm not going to explain in details the security algo used here, but think about this for a moment - if you are using dynamic second token device (that generates new token every few seconds) - what exactly it is we need to store and how will I differentiate you from the intruder next door who reconnects with the same ip and claims that he is you?

The logs will help me pinpoint why security algo did not work as expected.



Yes sure. In fact i know nothing about programming...

Just store the encrypted credentials in the client after the first challenge. It's secure.

    Edit/Delete Quote Complain
fullautotrading
 

Registered: Mar 2010
Posts: 593

 

08-28-12 10:40 AM

qed: slowly approaching the feature state ...

tuesday.png
This has been downloaded 253 time(s).

    Edit/Delete Quote Complain
travis
 

Registered: Oct 2002
Posts: 793

 

11-27-12 03:52 PM

Ok, now I am having problems with SSL (cfr. attachment): it causes my TWS to stop being updated and it disrupts my automated trading. And here, as usual, they say that IB suggested to simply disable the SSL:
http://www.elitetrader.com/vb/showt...threadid=218598

So let me get this straight: you enable the security token and the SSL for security, and if you don't keep it enabled, in case something goes wrong, you will not be refunded, says IB. But when you come across all the technical problems they suggest to disable it. Hmm, great. So I either run things smoothly and risk being hacked, or I accept having problems periodically, and then I am secure.

Fine, after disabling the security token because of all the problems (that now seem solved, but I don't want to risk it), I will now have to disable the SSL, too, because this problem went from never happening, to happening once a week, in the space of six months.

20121127_javax.net.ssl.jpg
This has been downloaded 27 time(s).

    Edit/Delete Quote Complain
    Page 21 of 22:   « First Page   12  13  14  15  16  17  18  19  20   21  22  
Post A Reply


Receive an email whenever a new post is added to this thread by subscribing to it.
 
Rate This Thread:

Forum Jump:
 

 

   Conduct Rules  -  Privacy Policy  -  Day Trader -  Day Trader Forum -  Best Trading Software -  Sitemap Copyright © 2013, Elite Trader. All rights reserved.    
 
WHILE YOU'RE HERE, TAKE A MINUTE TO VISIT SOME OF OUR SPONSORS:
Advantage Futures
Futures Brokerage & Clearing
AMP Global Clearing
Futures and FX Trading
Bright Trading
Professional Equities Trading
CTS
Futures Trading Software
DaytradingBias.com
Professional Trading Analytics
ECHOtrade
Professional Trading Firm
eSignal
Trading Software Provider
FXCM
Forex Trading Services
Global Futures
Futures, Options & FX Trading
Interactive Brokers
Pro Gateway to World Markets
JC Trading Group
Direct Access Trading
MB Trading
Direct Access Trading
MultiCharts
Trading Software Provider
NinjaTrader
Trading Software Provider
OANDA
Currency Trading
optionshouse
Option Trading & Education
Questrade
Canada's #1 Online Broker
Rithmic
Futures Trade Execution Platform
SpeedTrader
Direct Access Trading
SpreadProfessor
Spread Trading Instruction
thinkorswim by TD Ameritrade
Direct Access TradingAdvertisement
TradersStudio
System Building & Backtesting
Trading Technologies
Trading Software Provider
Trend Following
Trading Systems Provider