I've had vuln disclosures go bad before and after the rise in popularity of bug bounty programs, so I'm probably qualified to chime in here.
Before HackerOne, the default for a company that didn't receive vuln reports well was to threaten you and/or your employer with lawsuits.
This happened to me with Bullhorn and Intuit, despite my investigation and reports being unrelated to my employment. They ultimately went no where, but I imagine the conversation I wasn't present for was, at best, awkward.
Last year, under one of my aliases, I found a vuln in Credit Karma, and the H1 triage staff declared it out of scope. So I posted it on Github/Twitter.
Instead of threatening to sue, CreditKarma asked me to pull the tweets/gists and walked back the H1 triage decision and ultimately awarded a bounty for my finding.
Thus, I don't buy the chilling effects narrative the article tries to sell. It actually made security research more normalized than it used to be.
Just my unsolicited $0.02