Best Security Practices for IBKR Clients

Overview: 

IBKR goes to great lengths to keep client accounts secure. This document provides recommendations to safely operate and maintain your trading operations with Interactive Brokers.

 

Table of Contents

  1. Monitor your account
  2. Maintain Accurate Account Information
  3. Employ Safe Computing Practices
  4. Protect your Data
  5. Handle with caution pop-ups, unknown emails, and links
  6. Handle passwords securely
  7. Mandatory Secure Login System (SLS)
  8. IP Restrictions 

 

 

1. Monitor your account

  • Regularly check your account balances and positions through TWS and the daily statements available in Client Portal.
  • Immediately report anything suspicious by contacting Client Services through any real-time method (Live Chat or Phone Call) listed under ibkr.com/support .

 

2. Maintain Accurate Account Information

  • In the event that we detect unusual or suspicious activity, being able to contact you is essential.
  • Accordingly, you should always ensure that the contact information you have provided (e.g. telephone numbers, email address) is always accurate.
    • To update your contact information, log in to our Client Portal. From the main menu, select Settings > User Settings and go to the Communication panel.

 

3. Employ Safe Computing Practices

  • Lock your computer if you're leaving it for a period of time by setting up a password protected screensaver. Always turn off your computer when you have finished using it. This recommendation is imperative for mobile computers and highly recommended for shared machines.
  • Avoid accessing your brokerage account from public computers. Some of those may have been targeted by hackers and have a keystroke-capture software. If you must use a public computer, remember the following:
    • Use the virtual keyboard on the login window to avoid having your keystrokes captured.
    • Log out after accessing your account.
    • Never leave the computer unattended while logged in.
    • Clear the browser cache after logoff so that no sensitive information remains stored on the computer.
  • Regularly check for security updates and patches for your operating system and use the most current version of your browser.
  • Create separate profiles (user/password protected) if your computer is shared with a third party.

 

4. Protect your Data

  • Do NOT share personally identifiable information like your SSN, Credit Card number when answering an unsolicited email, phone call, text message, or instant message. In case of a doubt, ask for a name and a callback number, as well as an internal reference number for the communication.
  • Do not share files unless it's absolutely necessary. It's a smart idea to disable the file and printer sharing features, but if you decide to use these, make sure that you configure the access permissions with strong passwords, and only share for specific users.
  • Consider the encryption of your email communication:
    • It's important since it protects you from a data breach, and from the hacker to read your messages (the hacker won't have access to the information).
    • Either configure your email settings to encrypt your messages, or use an end-to-end encrypted email service (e.g. ProtonMail).

5. Handle with caution pop-ups, unknown emails, and links

  • Beware of phishing - phishers try to trick you into clicking on a link that may result in a security breach. Make sure that for sensitive information and login, you mouse over links and/or verify the website's address in your browser's address bar.
  • We recommend that you use a pop-up blocker (sometimes integrated in your browser) and set its security filter to the highest possible level. Then either add the IBKR website to your list of "trusted" sites, or disable your pop-up blocker while using our website.
  • Use email safely, and delete without opening messages that don't originate from a trusted source as they may contain harmful attachments or links, or may be an attempt to fraudulently obtain sensitive information. Turn off the "preview pane" in your email system as this function can allow some viruses to be executed even if you never open the email. Make sure that you add to your address book the IBKR email addresses.

 

6. Handle passwords securely

  • Use the maximum characters available and avoid simple or duplicate alphabetic and numeric sequences or passwords containing personal information.
  • Do NOT share your password with anyone.
  • Change your password frequently and do not use the same password for multiple systems.
  • Do not leave notes on your monitor, keyboard, desk or drawer to help you remember your passwords.
  • Use a password manager to store your passwords. This software will not only allow you to generate complex passwords, but as well to store them securely.

 

7. Mandatory Secure Login System (SLS)

  • The Secure Login System provides an extra layer of security to your IBKR account at no charge through the use of a free physical security device or IBKR Mobile Authentication. The enrollment in our SLS program is mandatory.
  • IBKR offers the following solutions:
    • SMS (automatic enrollment at account opening).
    • IB Key Authentication via IBKR Mobile (available to all our clients - requires a smartphone).
    • Digital Security Card + (available to accounts with a balance greater than 500K USD).
  • We support multi-2FA, meaning whenever possible, we recommend users who have an active DSC+ to also activate IB Key on their smartphone.
  • Click here for an Overview of our SLS Program (KB 1131)
  • Click here for an details on IBKR Mobile Authentication (KB 2260)

 

8. IP Restrictions

  • To prevent the login to your IBKR account from an unauthorized computer, enable IP Restrictions via the Client Portal.
  • With IP Restrictions active, login to your account on any of our platforms (Client Portal, TWS and IBKR Mobile) will only be permitted if the device you are using is connected to the IP address(es) you've previously designated.
  • Click here for further instructions on IP Restrictions

 

使用數碼安全卡+進行安全登錄

Overview: 

 

使用IBKR的數碼安全卡+安全地登錄任何IBKR程序,包括TWS、客戶端或網絡交易者(WebTrader)。

 

注:安全卡上的按鈕并非觸摸式感應,需要按壓操作。

1. 登錄賬戶時,像往常一樣輸入用戶名和密碼(圖1第1點)。如果用戶名和密碼正確,則會出現一個6位數挑戰碼(圖1第2點)。

圖1.

 

2. 拿出您的設備,按住“press”按鈕直至出現“PIN>”(圖2),輸入您在請求設備時設置的4位數PIN碼,然后按“OK”按鈕(圖3

圖2.                                                                  圖3.                                                         

3. 設備上出現“CHALLNG>”時(圖4),輸入登錄界面上給出的6位數挑戰碼(第1步),然后按“OK”按鈕(圖5)。

圖4.                                                                  圖5.                                       
    

4. 此時會出現響應碼(圖6

圖6.                                                          

5. 在登錄界面輸入8位數響應碼(圖7)。點擊登錄按鈕繼續登錄。如果時間太長響應碼過期,從上方第1步重新開始。

圖7.                                                               

注:安全代碼部分的顯示可能會因您登錄程序的不衕而有所不衕。

 

參考
  • KB1131:安全登錄系統概覽
  • KB2636:安全設備相關信息與程序
  • KB2481:有關在兩個或以上使用者之間共享安全登錄設備的說明
  • KB2545:退出后如何重新加入安全登錄系統
  • KB975:如何將安全設備退還給IBKR
  • KB2260:通過移動IBKR激活IB Key驗證的說明
  • KB2895:多設備雙因素系統(M2FS)相關信息
  • KB1861:安全設備相關費用
  • KB69:臨時安全碼相關信息

 

How to add a user to an existing IB Key instance - iOS

Overview: 

This page covers the steps required to add a user to the Authentication section in the IBKR Mobile app for iOS devices.

 

Requirements:
  • The IBKR Mobile app must be installed and IB Key Authentication already activated on this iOS device.
  • For more information on the installation and activation on iOS devices, please refer to KB2278.

 

Instructions:

1. On your iOS device, open the IBKR Mobile app.

     1.a. If the app opens with the login screen (Figure 1), tap on Services on the top-left corner (red arrow) and proceed with step 2

     1.b. If the app opens with your Home Page, Portfolio, Watchlists, or similar, tap on More on the bottom-right corner (Figure 2). Then tap on Two-Factor Authentication (Figure 3), followed by Add User (Figure 4) and proceed with step 3.

Figure 1.                                       Figure 2.                                       Figure 3.                                                                     

     

Figure 4.                                     

2. Tap on Authenticate (Figure 5) and then on Add User (Figure 6).

Figure 5.                                         Figure 6.

    

 

3. Read the instructions and then tap on Continue (Figure 7).

Figure 7.

3. Enter your Username and Password, and then tap on Continue (Figure 8). 

Figure 8.

4. An Authentication Code will be sent via SMS to the mobile phone number listed on your account (Figure 9). Enter this Authentication Code in the Activation Code field and tap on Activate (Figure 10).

Figure 9.                                                    Figure 10.

  

5. Depending on your smartphone's security settings, you will be asked to use your Passcode, Touch ID, or Face ID (Figure 11).

Figure 11.

6. If the activation has been successful, you will see a confirmation screen. Finally, tap on Done to complete the procedure (Figure 12).

Figure 12.

How to add a user to an existing IB Key instance - Android

Overview: 

This page covers the steps required to add a user to the Authentication section in the IBKR Mobile app for Android devices. 

 

Requirements:
  • The IBKR Mobile app must be installed and IB Key Authentication already activated on this Android device.
  • For more information on the installation and activation on Android devices, please consult KB2270.

 

Instructions:

1. On your Android device, open the IBKR Mobile app.

     1.a. If the app opens with the login screen (Figure 1), tap on Services on the top-left corner (red arrow) and proceed with step 2.

     1.b. If the app opens with your Home Page, Portfolio, Watchlists, or similar, tap on More on the top-left corner (Figure 2). Then tap on Two-Factor Authentication (Figure 3), followed by Add User (Figure 4) and proceed with step 3.

Figure 1.                                       Figure 2.                                        Figure 3.

    

Figure 4.

2. Tap on Authenticate (Figure 5) and then on Add User (Figure 6).

Figure 5.                                           Figure 6.

         

3. Read the instructions and then tap on Continue (Figure 7).

Figure 7.

4. Enter your Username and Password, then tap on Continue (Figure 8). 

Figure 8.

5. An Authentication Code will be sent via SMS to the mobile phone number listed on your account (Figure 9). Enter this Authentication Code in the Activation Code field and tap on Send (Figure 10).

Figure 9.                                                        Figure 10.

      

6. Provide your PIN then tap on Activate (Figure 11).

Figure 11.

7. If the activation has been successful, you will see a confirmation screen. Finally, tap on Done to complete the procedure (Figure 12).

Figure 12.

How to verify your identity using your Secure Login Device

Overview: 

Some tasks in Client Portal will ask you to verify your identity by using the Challenge Code/Response String method in order to proceed further.

This article will guide you in completing these tasks with the following Secure Login Devices:

-----------------------------------------------------------------------------------------------------------------------------------------------------------

Verify your identity with IB Key (iOS)

1. When you initiate a task that requires a verification, you will be prompted to enter Username and Password. Fill out the information and click on Continue (Figure 1).

Figure 1.

2. A Challenge Code will be displayed, along with a passcode field to enter a response (Figure 2). You will enter this Challenge Code onto your phone.

Figure 2.

3. Launch IBKR Mobile on your iOS smartphone, and...

     3.a. If the app opens with the home screen (Figure 3), select Authenticate then proceed with step 4.

     3.b. If the app opens with the login screen (Figure 4), tap Services on the top left (red arrow), select Authenticate (Figure 3) and proceed with step 4.

     3.c. If the app opens with your Home Page, Portfolio, Watchlists, or similar (Figure 5), tap More on the bottom-right (red arrow). Then tap Two-Factor Authentication (Figure 6), tap Generate Code (Figure 7) and proceed with step 4.

Figure 3.                                           Figure 4.
     

Figure 5.                                           Figure 6.                                            Figure 7.

          

4. Type the Challenge Code from Client Portal (see step 2.) into the corresponding field and select Generate Passcode (Figure 8).

Figure 8.

5. Use Touch ID or Face ID for two-factor authentication.

If Touch ID has not been activated, IB Key will prompt you to enter your smartphone's passcode. A response string will then be generated (Figure 9).

     5.1 If you use Touch ID, place your registered finger on the Home Button (Figure 9). A response string will then be generated (Figure 10).

Figure 9.                                                       Figure 10.
     

     5.2 If you use Face ID, look at your iOS smartphone screen (Figure 11). A response string will then be generated (Figure 12).

Figure 11.                                                          Figure 12.
    

6. Enter the response string from IB Key into the passcode field of Client Portal and click Continue (Figure 13).

Figure 13.

 

-----------------------------------------------------------------------------------------------------------------------------------------------------------

Verify your identity with IB Key (Android)

1. When you initiate a task that requires a verification, you will be prompted to enter Username and Password. Fill out the information and click on Continue (Figure 1A).

Figure 1A.

2. A Challenge Code will be displayed, along with a passcode field to enter a response (Figure 2A). You will enter this Challenge Code onto your phone.

Figure 2A.

3. Launch IBKR Mobile on your Android smartphone, and...

     3.a. If the app opens with the home screen (Figure 3A), select Authenticate then proceed with step 4.

     3.b. If the app opens with the login screen (Figure 4A), tap Services on the top left (red arrow), select Authenticate (Figure 3A) and proceed with step 4.

     3.c. If the app opens with your Home Page, Portfolio, Watchlists, or similar (Figure 5A), tap More on the bottom-right (red arrow). Then tap Two-Factor Authentication (Figure 6A), followed by Generate Response (Figure 7A), and proceed with step 4.

Figure 3A.                                            Figure 4A.

    

Figure 5A.                                          Figure 6A.                                     Figure 7A.

         

4. Type the PIN that you determined during the IB Key registration process and the Challenge Code from Client Portal into the corresponding fields, then select Generate Passcode. A response string will then be generated (Figure 8A).

Figure 8A.

5. Enter the response string from IB Key into the passcode field of Client Portal and click Continue (Figure 9A).

Figure 9A.

-----------------------------------------------------------------------------------------------------------------------------------------------------------

Verify your identity with Digital Security Card+ (DSC+)

1. When you initiate a task that requires a verification, you will be prompted to enter Username and Password. Fill out the information and click on Continue (Figure 1B).

Figure 1B.

2. A Challenge Code will be displayed, along with a passcode field to enter a response (Figure 2B). You will enter this Challenge Code onto your DSC+.

Figure 2B.

3. Turn on your DSC+ using the “press” button until 'PIN>' is displayed (Figure 3B). Enter the 4-digit PIN code you specified at the time you requested the device, then confirm with the “OK” button (Figure 4B).

Figure 3B.                                                              Figure 4B.                                                    

     

4. When 'CHALLNG>' is displayed (Figure 5B), enter the 6-digit Challenge Code from the Client Portal screen into the DSC+, then confirm with the "OK" button (Figure 6B).

Figure 5B.                                                              Figure 6B.                                       
    

5. A response code will appear (Figure 7B).

Figure 7B.                                                  

6. Enter the response string from your DSC+ into the passcode field of Client Portal and click Continue (Figure 8B).

Figure 8B.

Secure Login with Digital Security Card+

Overview: 

Securely log into any IBKR application, including TWS, Client Portal or WebTrader, using IBKR's Digital Security Card+.

 

NOTE: The buttons on your security card are not touch sensitive, but rather require to be pressed.

1. When logging in to your account, enter your user name and password as usual (Point 1 of Figure 1). If successful, a 6-digit Challenge Code will appear (Point 2 of Figure 1).

Figure 1.

 

2. Turn on your device by pressing the “press” button until the 'PIN>' display appears (Figure 2), enter the 4-digit PIN code you specified at the time you requested the device, then press the “OK” button (Figure 3).

Figure 2.                                                              Figure 3.                                                         

3. When the 'CHALLNG>' display appears on the device (Figure 4), enter the 6-digit Challenge Code from the login screen (step 1.) into the device, then press the "OK" button (Figure 5).

Figure 4.                                                              Figure 5.                                       
    

4. A response code will appear (Figure 6)

Figure 6.                                                          

5. Enter the 8 digits of the response code into the login screen (Figure 7). Select the Login button to proceed. If the passcode expires, start over from step 1. above.

Figure 7.                                                               

NOTE: The Security Code field will look slightly different depending on the application you are logging in to.

 

References
  • See KB1131 for an overview of the Secure Login System
  • See KB2636 for information and procedures related to Security Devices
  • See KB2481 for instructions about sharing the Security Login Device between two or more users
  • See KB2545 for instructions on how to opt back in to the Secure Login System
  • See KB975 for instructions on how to return your security device to IBKR
  • See KB2260 for instructions on activating the IB Key authentication via IBKR Mobile
  • See KB2895 for information about Multiple 2Factor System (M2FS)
  • See KB1861 for information about charges or expenses associated with the security devices
  • See KB69 for information about Temporary passcode validity

How is my IB Canada account protected?

The Canadian Investor Protection Fund (CIPF) is sponsored by the Canadian regulator (IIROC) to ensure client assets held by a Canadian investment dealer are protected if a member firm becomes insolvent. IB Canada is a member of the CIPF which offers insurance against member default for amounts up to CAD 1,000,000. Covered assets include cash, securities and commodities and will depend on the account type:

Non-registered accounts (Cash, Margin, TFSA)

1,000,000 CAD for any combination of cash, securities and commodities under all non-registered account types.
For assets held in a joint account or under a corporation, the percentage interest is added towards the same total.

Registered account (RSP)

RSP accounts are treated as "Separate Account" and are eligible for an additional 1,000,000 CAD coverage. Additional details can be found on www.cipf.ca.

Please note, IB Canada accounts receive CIPF protection in lieu of SIPC protection.

How to use Voice callback for receiving login authentication codes

Background: 

 If you have SMS enabled as two-factor authentication method, you may use Voice callback to receive your login authentication codes. This article will provide you steps on how to select voice callback when logging in to our platforms.

 

How to use Voice callback
 
You may select Voice if you do not receive your login authentication code. You will then receive your login authentication code via an automated callback. Follow the instructions below, depending on which platform you are trying to login to.
 

 

Client Portal

1. Click on "Didn't receive a security code?"

2. From the two options, select "Voice" and wait for the callback.

3. After selecting Voice, you should receive the callback within a minute. Please wait for the callback and be ready to write down the code that will be provided over the callback.

 

TWS

1. Click on "Request new Security Code"

2. From the two options, select "Voice" and click on OK. Then wait for the callback.

 3. After selecting Voice, you should receive the callback within a minute. Please wait for the callback and be ready to write down the code that will be provided over the callback.

Note: Voice callback for the TWS is only available in the LATEST and BETA version.

 

IBKR Mobile - iOS

1. Click on "Request New Code"

2. From the two options, select "Voice" and wait for the callback.

 3. After selecting Voice, you should receive the callback within a minute. Please wait for the callback and be ready to write down the code that will be provided over the callback.

 

IBKR Mobile - Android

1. Click on "Request New Security Code"

2. From the two options, select "Voice" and wait for the callback.

 3. After selecting Voice, you should receive the callback within a minute. Please wait for the callback and be ready to write down the code that will be provided over the callback.

 

References:

 

IB Key Challenge / Response method and missing notifications

In case your smartphone is unable to receive IB Key notifications, you can still complete the login process using the IB Key Challenge/Response method, described on the following pages (according to your device operating system):

The same information applies to you if your phone has no Internet connectivity (you are in roaming, out of coverage, without an active mobile data plan, etc.)

If your smartphone is unable to receive IB Key notifications despite having Internet connectivity, we recommend you to perform the steps outlined in IBKB3234.

 

雙因素保護—移動IBKR驗證

Overview: 

在IB,我們致力於通過雙因素驗證登錄保護您的賬戶。在雙因素驗證模式下,只有通過使用兩項安全因素才能訪問賬戶,即“您已知的”(用戶名和密碼)和“您已有的”(工具生成的隨機密碼,將在用戶名和密碼后輸入)。 雙因素保護旨在降低網絡黑客(其可通過惡意軟件或社會工程陷阱取得您的密碼)訪問您賬戶的風險。

盡管IB提供多種雙因素選擇,但移動IBKR驗證普遍被認為是最便於訪問和操作的方式。下方列出了該應用程序的一些便利性因素。

 

1. 始終可用:
您總是會隨身攜帶手機,這也就是能讓您安全訪問IB賬戶的工具

2. 便利:
無需攜帶、跟蹤和注意其它設備。如果丟失或更換手機,IB客服也隨時能幫助您恢復該應用程序,讓其正常運行。

3. 快速激活:
程序下載后几分鐘內,您便可用其進行驗證登錄。

4. 無需郵寄、運輸或退還:
不會有寄送延遲,也不會因為電池耗盡而要退回設備。只需一次快速下載便可使用。

5. 用我們的無縫驗證實現安全且快速通暢的登錄:
登錄交易平台或賬戶管理時,您只需輸入用戶名和密碼 - IBKR會向您發送通知,您再使用IB Key協議用指紋或PIN碼(具體取決於您的配置)完成驗證。

6. 允許多個使用者用衕一個應用程序進行驗證:
如果您個人的IB賬戶有一個安全設備、您與配偶的聯名賬戶有一個安全設備、您的公司賬戶也有一個安全設備,那么知道所有這些使用者(還可以有更多)現在都可以用衕一個應用程序,您一定會非常高興。

7. 所有智能手機都可使用:
如果您用的是iPhone,可直接從蘋果應用商店下載移動IBKR。安卓手機用戶可從谷歌電子市場獲取該應用程序。中國客戶可以從百度手機助手或360手機助手上下載。

8. 可離線運行:
即使手機離線(如正在休假或信號不好),您仍然可以使用移動IBKR驗證。盡管無法使用無縫驗證,但該程序仍可以生成您訪問賬戶和進行交易必須用到的驗證代碼。

9. 重置密碼安全傳輸:
安裝了移動IBKR并激活了IB Key驗證后,您便可讓IB客服將臨時密碼以一種安全的方式發送到您的手機,而無需通過短信或其它方式。

10. 內存占用量小:
即使是限制最嚴格的數據套餐也可以下載移動IBKR,其安裝在手機上不會占用系統資源。該程序的大小及其運行時的資源占用量都已在不影響安全性能的前提下降到了最小。

 

有關移動IBKR驗證的安裝、激活與運行,請參見KB2260

Syndicate content