I remember thinking they could have at least used hashes of registry entries to detect the modules they were looking for if they wanted to protect the identity of target, but then again, the processor load of the hashing operations would have been a significant IoC. Stuxnet was a straight tactical hack to solve a specific problem, which was to delay that nuclear program. It was not just a threat or demonstration of capability to serve as a deterrent.
An example of a demonstration of capability was the silk road arrest, where the FBI mainly used it as a signal to create uncertainty about the absolute security of Tor hidden services, so that people understood they did not have impunity. They didn't break tor, but they showed tor wouldn't protect you if they wanted you. Stuxnet wasn't about demonstrating that they could get at you, it was to delay the nuclear program to give time to negotiations and potential outcomes other than iran achieving a weapons program.
What we call 'cyber' now is in support of variously tactical and strategic objectives, and while the criticisms of the code are valid, it's worth evaluating the tools in that higher level more abstract context as well.