TLS/HSTS is still subject to CA attacks, e.g. diginotar.
CA/X.509 is a complex stack too.
> TLS mitigates attacks that can be executed by malicious exit nodes (or WiFi networks, or ISPs), that is the whole purpose of TLS.
A malicious exit node could refuse to serve some websites. This seems a minor risk though.
Reducing load on exit nodes is a technical benefit that's in that blog post.
Another benefit to using Tor onion services for large sites is that the Tor circuit ID can be used as an additional key in an IP rate limit cache. This helps block Tor bots (on the basis that establishing a Tor circuit is expensive).