What pisses me off it that they say they do this for security. It changes absolutely anything.
They really think that malware developers will say "oh no! I need to submit a picture of an id card to sign my malware! It's literally impossible to submit a jpg of a stolen id card, I'm ruined and out of a job!"
What does it change? Waste 20 minutes of some malware developer while they register under a stolen id? They already have a system that scans for known malware and automatically remove it.