Egor privately contacted my little site a couple weeks ago to let us know we had a vulnerability with the redirect issue. At first, we didn't quite understand it, but once we dug deeper, it is a pretty major issue.
Simply put, we use ElasticEmail to send out email from our service. They have a feature called 'custom tracking domain' where you can setup tracking.your_domain.xyz to enable link tracking of emails you send out. This is great except that the url is something like this: tracking.your_domain.xyz?redirect=urlencode(some other domain) <- EE will then do a redirect to whatever is specified in there.
Because we offer facebook connect authentication on our site, this created a security hole for us based on what Egor has discovered. In other words, because we setup some simple configuration of some 3rd party service that happens to allow for redirects, we are now exposing our users auth tokens. Doh!
The solution to fix this is to simply not enable tracking.your_domain.xyz, but now that we've turned that off, old links in emails are broken. If EE had tinyurl'd the links they send out, this wouldn't have been an issue because it wouldn't be an open redirect service. The emails would have to go through them, get rewritten and then they would store the unique ID to do the redirect. Yes, we've contacted EE about it and they are looking into it, but probably not seriously since it isn't really their bug per se. In a way, this is similar to what FB is saying to Egor (not our issue), but the fact is that a simple bit of configuration by people using these systems can really cause a lot of problems.
In the end, it all really means that you have facebook connect on your site, you absolutely need to do an audit of your code and 3rd party systems and make 100% sure that you don't have any open redirects on your domains. This is a lot harder than it sounds.
As time goes on, I really hope we move to systems like Persona which haven't had these sorts of issues (so far). We also support Persona login on our site (as well) and it has been excellent. Being an open standard and allowing for multiple identity providers makes the chances of 'wontfix' a lot less of an issue.