Any idea if I need to make any changes to read it from web.config instead of app.config?

If I put Application("varPassword") = abcdin my global.asax, is that safe, or can bots or other things read that my password is abcd? If web.config file does not exist inside the folder it will create an empty web.config file and empty section inside it and then will encrypt it(Give it a try). Apr 9, 2010 I created a web setup project. I'm lost.

