Comment by charcircuit
20 hours ago
I personally would support automatically trusting self signed https certs since their key is typically secured under the same safety as the hidden service's key. And even when they are not the browser has no warning when you get downgraded to HTTP on an onion compared to a regular site.
Trying to push hidden services to stay on HTTP is going against what the rest of the web is doing and as a minority of web traffic it really should be aligned to the rest of the web and also require HTTPS. Yes, it's technically wasteful, but reduces both work and security risk by keeping security models aligned with the rest of the web.
And it breaks Javascript as a lot of APIs only work when the site is served via HTTP - which .onion sites won't be usually. Tor browser treats .onion sites as secure content, but not your regular browser using TOR via proxy.
Who would issue the certificates?
The "self" in "self-signed" means "you"
There's no point teaching the browser that self signed certificates are secure instead of teaching the browser that onion addresses are secure.