What prevents someone from misconfiguring apache such that /config.php is browsable? e.g. shouldn't there be a mention of setting up .htaccess?