Re: How secure are appsettings in web.config?

From: Cowboy \(Gregory A. Beamer\) (NoSpamMgbworld_at_comcast.netNoSpamM)
Date: 11/25/03


Date: Tue, 25 Nov 2003 09:54:46 -0600

In theory, very safe, as the config file is tied to the ASP.NET runtime. In
reality, who knows? Hackers are going to look for this type of information
and it is open text (in the 1.0/1.1 framework, at least). I would encrypt;
there are some good articles on MSDN for using the machine key to encrypt
secrets. In fact, the http://msdn.microsoft.com/architecture site has a
treasure trove of books on a variety of topics.

-- 
Gregory A. Beamer
MVP; MCP: +I, SE, SD, DBA
**********************************************************************
Think Outside the Box!
**********************************************************************
"Tim Wood" <tww@nomail.com> wrote in message
news:u3g$sB2sDHA.2380@TK2MSFTNGP09.phx.gbl...
> Just wondering how safe it is to include sensitive information such as a
> database connection string in web.config.
>
>


Relevant Pages

  • Re: Michael, fan tribute
    ... It's practically impossible to practise safe hex when the OS insists on trying to run arbitrary code from arbitrary external sources without even stopping to ask you if it should. ... I whine and complain about the holes and problems in XP as the next ... hackers started targeting that one, it would have holes as well. ...
    (rec.autos.sport.f1)
  • Re: My 2@ Worth on Firewalls
    ... > exposing the names of 10,000+ malicious hackers. ... > installing a firewall at all. ... > system is 100% safe and this is talked about all over the place. ...
    (comp.security.firewalls)
  • My 2@ Worth on Firewalls
    ... exposing the names of 10,000+ malicious hackers. ... installing a firewall at all. ... Nortons Firewall is all. ... system is 100% safe and this is talked about all over the place. ...
    (comp.security.firewalls)
  • RE: Password storage tool?
    ... Things like service accounts, Domain Registrar accounts, ... Right now we do the manual information to an envelope that gets ... stored in a safe. ... Thing, but if we can securely encrypt it, it makes it a lot easier ...
    (Security-Basics)
  • Re: Do I dare to install NMAP?
    ... >> Is it safe to install NMAP on my pc? ... After all it's written by hackers ... > IT'S safe, as long as you get it from the official website. ... *nixies running it. ...
    (comp.security.firewalls)