Aren't you comparing Colin's iframe with a level of security unobtainable to normal Stripe developers? If you just use Stripe's JS interface the way they tell you to, you're not strictly speaking benefiting from Stripe's HSTS or XFO; your site still needs to defend against clickjacking and SSL stripping.
I feel like Colin built this little thingy to solve a real problem --- that by adding Stripe to his site, he was giving Stripe control over his site, and his site hosts information more sensitive than credit cards --- and people are piling on because his solution to his little problem doesn't solve every other imaginable security problem.
This would be less galling if the kinds of sites using Stripe today weren't almost uniformly rife with application security flaws that defeat most of the good intentions that Stripe has.