Vendors who don't provide some secure channel to send findings to are already subject to vigilante-style disincentives: if you don't provide a key, researchers will drop zero day on you publicly. Remember, public drops used to be the primary way things got disclosed.
You appear to think we need to worry about vendors gaming the system. But on the researcher side, the standard definition of "responsible disclosure" is, "I wait 60 days after I send you something and then I go public whether you say OK or not". That isn't just my take on the situation; it's what actually happens.
It's starting to look like doing this for open source projects is a good start. They seem to be less capable at this, try to hide the vulnerabilities more, and reporting to them is much harder and well organized. Also, based on my experiences with how the Ruby projects does it's bullshit security, the users could really benefit.
You appear to think we need to worry about vendors gaming the system. But on the researcher side, the standard definition of "responsible disclosure" is, "I wait 60 days after I send you something and then I go public whether you say OK or not". That isn't just my take on the situation; it's what actually happens.