Earlier quoted context omitted.
Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.
If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…
Conversely, if you accuse the person who tells you the door is open of stealing from you and threaten to call the police, should you really be surprised if next time that happens they tell someone, maybe in exchange for a cut of the profit?