Do not put the .htpasswd file in the same directory. If it's there, someone could easially grab it and know all the users on the system, plus have an easy time at cracking the passwords.

The logo site uses .htaccess for logins, and the password file sits in a very restricted folder in my home directory, and no web address can access it.