It's odd that they didn't want to use the machinekey (though maybe there's a reason for that), or an appsetting / custom config section for the encryption info - instead encouraging you to use the same tickets across all of your environments.
Also odd is that when you pass a string it uses UTF8 [or really any variable length encoding] to specify the IV and secret key (instead of taking a base64 string, which would encourage the use of actually random values).
A third oddity is that the cryptotransforms are never reused - I know that some can't be reused (and there is a property to indicate this) but the solution reconstructs a transform regardless of whether this is the case.
I've been bitten by the random "Invalid Forms Authentication Ticket" issue a couple of times (random windows updates breaking stuff, w00), and while it is tempting to implement your own auth layer (particularly if you have a number of apps that are running on different .net versions that need to share authentication tickets), it doesn't strike me as the best solution to the problem - indeed, if you have a hetrogenous system (ie are using asp.net as well as ASP MVC, or you've got some other product that is using asp.net for you that you don't control [sharepoint, SSRS, any of the others]), now you probably have two problems instead of one (unless of course, you go out and rewrite all of the asp.net controls which just go ahead and use the FormsAuthentication class).
I really like the solution given here, but it's only suitable for a subset of applications, and I wouldn't use it without a few modifications.