Earlier quoted context omitted.
You seem to be contradicting yourself. Businesses are asking for Stripe to verify identity. These businesses just need verification, not copies of documents, but Stripe makes them available anyway. That's the whole contention. As a consumer, I would expect Stripe would do the verification and give the business partner the result, but not all the data they used to get the results themselves.
I actually disagree with this as well. The Hacker News user is not the average user. The average user has no idea what Stripe is, they assume that the business requesting a verification will have access to anything they submit. I know this because we use Stripe Identity ourselves (in beta) and user's have no idea that Stripe and us are different companies.
Doesn't that imply that if there's a security breach at Stripe, that your users will blame you [too]