They've already contacted the company and reported the vulnerabilities, and likely were much less anonymous in the process.
Generating PGP keys for future claim would require you to keep a copy of the private key, this copy can be seized if a criminal investigation does happen.
>This isn’t poor advice. Speaking for myself, I choose to give this advice as a security professional and someone who has had to make various disclosures, both “responsible” and “full”, and of the latter, with and without the cooperation of the company.
So have I and this is a poor advice, especially these days with some of the regulation that is popping up.
The line which differentiates between a paid bounty or a PR piece on your website and criminal prosecution is how you handle the situation the law applies identically to both there are no legal provisions for doing unsolicited penetration testing because you say you're a good guy, heck in the UK for example the exemption form that companies sign do not actually exempt the individual tester from being prosecuted by the crown it can only be used as a legal defense, in Germany the possession of "hacking tools" is illegal without a cause, and there are tons of other nuances for each and other country and jurisdiction in the world.
Telling people to just post stuff on seclists especially after already being in contact with the company is a terrible idea, so while I do appreciate you might have had different experience it doesn't mean you handled it correctly nor does it mean you are giving a sage advice.