Proton also uses HTTPS for their onion site, and they used the same certificate provider as Facebook did for theirs, Digicert, per this page:

https://proton.me/blog/tor-encrypted-email

In the above blog post, they seem to imply that they made HTTPS mandatory for Proton Mail over Tor for security reasons.

The best is to refer to official Tor project documentation for .onion over https: https://community.torproject.org/onion-services/advanced/htt...

tl;dr: Pressure from browsers, enterprise, and the overall ecosystem to use HTTPS (e.g., unavailability of advanced web features without HTTPS) is pushing for the use of HTTPS without exception, even for .onion sites with no significant technical advantage.

Tor browser doesn't warn on http though and I feel like 90% of folks use it exclusively.