For the rest: if you have standards or expectations for the security of any site than handles your personal information, you are bound to be disappointed. I am less worried about the information I post to a site like Healthcare.gov than I am about online banks. How secure do you think new, production, real-money online banking sites are? Here's a hint: you have more to worry about than open redirects.
Absolutely. The people who will pay the price for that design philosophy are not the ones making the decision to use that design philosophy.
It really doesn't matter if poor security engineering is the common case, we should expect better from a modern system with the budget of a federal project and the legal requirement that we use it.
Nothing is secure from the start. Everything has bugs.
Sure, all aspects of programming are subject to bugs. My concern with the site is an apparent lack of design for security. Admittedly the linked article only talks about symptoms, I'm inferring poor design from a previous article which said the developers put security at the bottom of the list of priorities.