It is. You want to download Tor in some hard to track way, you probably shouldn't use an easily trackable source. There are better options including getting sent an email and torrents.
And given the scope of the attacker, fingerprinting by size and server is trivial so easily https adds nothing related to anonymity nor security.
And given the scope of the attacker, fingerprinting by size and server is trivial so easily https adds nothing related to anonymity nor security.