I know it is possible to encrypt the connection-string stored in the web.config,
And I know you could never be too safe, but since the web.config cannot be viewed or downloaded, why is it needed? in what way is it more secure?
[EDIT:] I’m not using a shared-hosting server.
If you deploy your website to a customer’s web server and want to keep the credentials secret.