The inescapable fact about Tor is that its traffic patterns make you stand out prominently. Just the fact you’re using it automatically makes you interesting and worthy of a closer look. All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?
There is also the inescapable fact that Tor was created by US Intelligence, specifically the US Naval Research Lab[0]. And according to FOIA documents it continues to receive a huge chunk of funding & resources from US Intelligence, particularly from the United States Agency for Global Media (formerly the Broadcasting Board of Governors), which supervises our propaganda channels Voice of America and Radio Free Europe…
Having a bunch of Tor site certs in your MacOS keychain has its own issues, so what is really needed is a way for Tor browsers to accept those certs directly without using the OS trust stores. The current practice of authenticating the remote site by PGP signature would remain more or less the same - you just wouldn’t have exit nodes sniffing traffic.
I’m also convinced that the whole reason Google has pushed TLS so hard isn’t some noble quest to protect people’s privacy and freedom of speech - it’s more to keep people from blocking their advertisements, which isn’t nearly so sexy an argument, but it has brought good benefits for a lot of people.