At the end of the day your enemy has no ethics, and we share the public internet with enemies. If paying to find security flaws means it's more likely people will find your flaws rather than sell them to someone that will use them for nefarious means then it is the better bet.
Making an argument for what's practical and what's ethical are two different things. My comment was about the latter. Yours appears to be about the former.
Ransomware victims have sometimes found it practical to pay the ransom. They're still victims of extortion.