Introducing the Dropbox bug bounty program
blogs.dropbox.com
blogs.dropbox.com
Back in the old days far too many companies had very poor processes for dealing with security issues. Either it was impossible to give the report (stuck in CS hell), you'd never hear feedback (e.g. fixed, WONTFIX, etc), you may be threatened with criminal/civil prosecution, and you most certainly wouldn't be credited or acknowledged.
Now, if nothing else, at least the process is well documented end-to-end. Even if we ignore the "debate" over compensation, at least all the other problems are now solved. If you throw on top of that a small "thanks" payment for finding the bug, you now not only solve the old problems but you give people a legitimate reason for responsible disclosure beyond morals.
That's really the core of this, doing the right thing should make rational sense as well as moral sense. Then the bug finder has no real reason to do anything except the right thing. The only reason not to disclose responsibly now is spite (or in Google's case a strict adherence to policy no matter how little sense it makes).
Or you might go for a search for "dropbox" here (that comes in handy if there are a lot of reports): http://h1.nobbd.de