I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…
We've had a handful of these that we've paid out for small issues over the years. Things that are _technically_ security issues, but not something that affect us or are exploitable in a meaningful way. $50 a few times a year is stupid cheap to build a reputation of actually paying out security researchers. Among the junk, we've had a few legit bounties submitted. That alone is worth the noise these "beg bounties" cre…
It also helps that we have very clear rules and defined scope: we've put out of scope the usual suspects and researchers rarely argue when we point out they should have read the rules better before submitting.
Regarding bounties, my yardstick rule is that if a report made us reconsider our practices and change something on our side, then it's worth a bounty, even small. If not, then no bounty far ya, simple as that.
Also, I don't remember getting a disclosure report where they would ask for money before disclosing the vulnerability, I don't think it's that common. Still, this would go straight to the spam folder.