2: If you generate crash dumps, scrub the dumps when you generate them. Some crash reporting services offer to do this automatically.
3: If you are writing anything client/server, where you control the server and the client runs on a users machine, never trust the client. Expect that it has been hacked, is being debugged, and is actively hostile.