diff --git modules/system/system.admin.inc modules/system/system.admin.inc
index 2af689a..0deaba5 100644
--- modules/system/system.admin.inc
+++ modules/system/system.admin.inc
@@ -1759,7 +1759,7 @@ function system_file_system_settings() {
     '#title' => t('Private file system path'),
     '#default_value' => variable_get('file_private_path', ''),
     '#maxlength' => 255,
-    '#description' => t('A local file system path where private files will be stored. This directory must exist and be writable by Drupal. This directory should not be accessible over the web.'),
+    '#description' => t('A local file system path where private files will be stored. This directory must exist and be writable by Drupal. This directory should not be accessible over the web. For example, place the directory outside of your Drupal installation directory, or block access to it through your web server configuration. For more information about securing private files, see the <a href="@handbook">online handbook</a>.', array('@handbook' => 'http://drupal.org/handbook/modules/file')),
     '#after_build' => array('system_check_directory'),
   );
 
