I am rather impressed. 37Signal's application security response team is on the ball. Once they received the notification about their open redirects, they were deploying the fix within 5 minutes. I will happily work with them again.
http://37signals.com/security-response