Welcome to Personal Stock Monitor user forum. You must have an account to post to the forum. See the forum instructions page for some instructions on how to use the forum.
Subscribe to RSS Feed
Personal Stock Monitor Users Forum -> Trading Account Security
Not logged in.
2010-06-19 22:21:11
1 of 3
#2279
Love the product and about to make my third purchase. There is one area I would like some feedback on though.

I am going to be using PSM with a TDAmeritrade account. I do worry a bit about two security areas. First, the "Man in the middle" issue. Can I be confident that my account password and info is not leaving my computer un-encrypted?

Second, I worry a bit about scripts. If someone writes a script and you install it without question, it is really up to you. However, is DTLink screening recommended scripts for security, and do you have insulating account information from security beaches as an in-house development priority?

Thanks
Posted by: Timgrspace
2010-06-19 22:26:29
2 of 3
#2280
in reply to #2279
Also - A quick note:

I'm sure this is on the table, but are you planning on upgrading the internal browser soon?

Posted by: Timgrspace
2010-06-21 10:07:45
3 of 3
#2281
in reply to #2279
Timgrspace wrote
I am going to be using PSM with a TDAmeritrade account. I do worry a bit about two security areas. First, the "Man in the middle" issue. Can I be confident that my account password and info is not leaving my computer un-encrypted?

Yes. Since we use TD AMERITRADE's official API, everything is encrypted using industry-standard SSL just like in your browser. We have also been certified as an official partner application by TD AMERITRADE.

Timgrspace wrote
Second, I worry a bit about scripts. If someone writes a script and you install it without question, it is really up to you. However, is DTLink screening recommended scripts for security, and do you have insulating account information from security beaches as an in-house development priority?


Scripts don't have access to your login or account info anyway, but as part of the API they have do access to your transaction history. All extensions we distribute are digitally signed by us. Any third party extensions you may download from elsewhere would not be signed and would pop up a warning. If you install them, or run other third party scripts, then you accept the consequences.
Posted by: Anatoly