> So what do you say about the idea that it creates a disincentive to find security issues...
If a company is disincentivized to look for security holes because it's highly likely it will find them; that company is on the fast-track to failing.
> If they did an adequate investigation, using a 3rd party service, and found no evidence of my data being accessed by a 3rd party
They found no evidence of data being accessed, but they also don't share how this particular system tracks data that is accessed. This system was vulnerable for 2-3 years. What if you left your car at my house and you found a dent on it, but I claim that I didn't have any security footage of someone damaging your car without mentioning that I don't actually have security cameras.
> I'm willing to bet your service has security holes in it...
You're right, and it I find that my NTP service is exploitable and anyone can DDOS me I'll fix it and move on. There's no need to disclose that I'm an idiot when it doesn't affect other people. But when I accidentally leave my servers mis-configured and my API unprotected against unauthorized access I would make a post about it. We're not talking about an arbitrary vulnerability that lets people echo hello on a Google server. They left data exposed. I would like to know if it involves me.