I never said they weren't allowed to care about money in general; only that it shouldn't be their primary motivation for disclosing a security vulnerability. Even if it is, I'm not saying that makes them a bad person either; only that they can't use the white hat label as the author did in my second quote.
Says who? People who would never commit a criminal cyber-act are still allowed to care about money.