Make .git directory web inaccessible

I have a website that I use github (closed source) to track changes and update site. The only problem is, it appears the .git directory is accessible via the web. How can I stop this and still be able to use git?

Should I use .htaccess?
Should I change permissions of .git?

Create a .htaccess file in the .git folder and put the following in this file:

Order allow,deny
Deny from all
