These are mostly bad examples, and pretty much none of them are examples of the phenomenon being talked about on this particular subthread:
1. Keeper is suing Dan Goodin, a reporter, for (I think?) defamation. (Keeper is evil and you should never use them, but they're not pursuing the researcher under CFAA or DMCA).
2. Chris Vickery found a database backup of a whole company, analyzed it and found that they were shady, and published directly from the database backup. That's not really vulnerability research, and is a bit akin to finding a vulnerability and then using it to dump an account table to Pastebin.
3. PwC C&D'd (but didn't sue) a firm called ESNC. The software ESNC was testing was available only under an NDA license; I assume ENSC got access transitively through a client. This happens a lot in enterprise pentesting. ESNC published anyways, and nothing happened.
4. DJI rescinded KF's authorization to continue testing when he refused to accept the terms of a bounty (which included both disclosure limitations [which may or may not have been reasonable] and a promise not to do post-compromise pivoting [which is entirely DJI's prerogative]). KF rejects the bounty terms, and DJI legal gets involved and demands that he delete any DJI IP or secrets he's taken. This is unfriendly, but not a lawsuit.
We're talking about the threat of lawsuits, right? Can we be so sure that the word "lawsuit" was never mentioned in any of those discussions?
The predicate at the root of this thread is "starting to file lawsuits or take legal action", against researchers.
Maybe a better way to put it: it's hard to see how any of the examples in this article would be addressed by Dropbox's VDP.
That's a big leap.
Given the rather asymmetric nature of the power in these interactions, even something as simple as just being responded to with a legal letterhead rather than an email from the security department has a stifling effect I'd argue.
Which example from that article would be addressed by Dropbox's VDP?