SQL Server - Storing the sensitive credentials in XML file and placing it in webserver(IIS)

Asked By karur krishna madhu on 10-Jan-14 05:51 AM
I have seen a new application where the architecture has been designed in a way that the sensitive information is being stored in an xml file and being put in web server(IIS).what are the pros and cons of this? on the flip side database has more features of securing the credentials then why move the info to an xml file and place it in web server? this is a mobile application UI coupled with a WCF rest based service(JSON format message transfer) with Oracle as the database.
Robbe Morris replied to karur krishna madhu on 10-Jan-14 08:16 AM
Well, as long as the xml isn't under the root of the web site and browsable, the major security concern is someone getting access to the web server itself.  Absent that, isn't hurt.  Lots of apps store secure info in the web.config.

Ideally, that information would be stored in an encrypted fashion and the dlls for the .net app obfuscated.  But, that rarely happens with web apps.
karur krishna madhu replied to Robbe Morris on 10-Jan-14 08:27 AM
Hmm ! Or could this be the reason. if the credentials are stored in db then the wcf service has to hit the db and fetch the data instead of that the service can pull the data from the web server(even though it has to ping the web server) and read the xml file content. which is the better approach hitting the db multiple times or hitting the web server multiple times? subtle difference is there which is creating chaos for me in this topic?
Robbe Morris replied to karur krishna madhu on 10-Jan-14 08:29 AM
From a security perspective, no not really.  The WCF service should be caching this information or holding it in a static variable so the database only had to be queried once.
karur krishna madhu replied to Robbe Morris on 10-Jan-14 08:41 AM
yeah! may be