While a lot of the security problems they have could indeed be fixed, I think it's worth noting a couple things.
* The Snapchat API is fundamentally insecurable as it exists today. The problem is not that Snapchat could have secured their API against unauthorized access and simply failed to do so, it's that their API cannot possibly be secured, AND they happened to make some bad mistakes along the way. Even a serious security team would have been unable to lock everything down. They might have locked some of these issues down, but they would not have gotten all of them.
* So, while I sympathize with the feeling that Snapchat is anti-OSS and anti-hacker, realistically, I also sympathize with Snapchat's position. They don't have that many options. What are they going to do? Their public position -- i.e., that you should not break their TOS -- does not strike me as especially unreasonable considering that investing millions into security will still not give them a bulletproof solution.
* Also worth noting is that Snapchat does not unilaterally ignore security inquiries, or at least, they did not ignore me. I emailed them personally and the response I got (from a high-level employee) was warm and encouraging. I did not get the cold shoulder. In fact, I found our interactions quite pleasant, and it made me want to help them lock things down.
Ultimately I think it's easy to write off the team as just a bunch of incompetent fools, but let's be realistic here: it's easier to break things than make them provably unbreakable.
Again, yes they've made some bad mistakes, but posturing about breaking a system that cannot be secured is perhaps not the best use of Gibson's obvious talent. The same also goes for the many other security researchers who've audited the API.