"Your Basecamp Classic URL (which looks like yoursubdomain.basecamphq.com) stays the same. New Basecamp accounts are hosted on the basecamp.com domain. New Basecamp accounts don't have subdomains, so all accounts are at basecamp.com."
I would expect the guy who found an issue with GitHub to report it to them. Yes, the rails people could have, should have.. But they explicitly asked "him" to report and there is no word on whether he did it or not.
If an app makes it possible to do SQL injections, whose fault is it?
What Rails have done is to have a particular default (whose correctness can be debated) and document how it can be exploited and how to safeguard from it.
In Snapier, it will be better if you have a message why you are asking for emails. More importantly, provide a message which is a little more than "Thank you very much" when I enter my email. Though I got an email within a second, it will be more user friendly to give a "We'll connect back soon" in the site itself.
Also, in the email you mention 'check us out on Twitter' but fail to provide the twitter id.
Just my two cents. If any of that sounds badly phrased, I blame the clock for showing 3 AM. Cheers :)
If the original title begins with a number or number + gratuitous adjective, we'd appreciate it if you'd crop it. E.g. translate "10 Ways To Do X" to "How To Do X," and "14 Amazing Ys" to "Ys." Exception: when the number is meaningful, e.g. "The 5 Platonic Solids."