Stripe has one fairly major advantage over PayPal in its Javascript library which insulates the merchant from handling the credit card information thus making PCI compliance more realistic.
So maybe Stripe is secure, but they might want to work on appearing more trustworthy.
When I've used PayPal as a customer, it asked for my credit card on its own domain, not the merchant's. Doesn't that insulate the merchant from handling credit card details at least as well as Stripe's API does?
Their implementation is both elegant and smart. Even easier than Braintree.
So yes, passive network sniffing won't work with Stripe's iframe being loaded over HTTPS, but this does not protect against any type of "active" man in the middle attack.