I find the problem with storing that data in the registry is that by using regedit, you can see the "secure" data.

By having it in my source code, I control who can see it (nobody but me).