The link I provided [1] has coinmarketcap.com that is forced HTTPS but not sure if that was or not.
There's some discussion of known Comcast injection here: https://news.ycombinator.com/item?id=15890551
The response from Comcast was [2]:
> This is our web notification system, documented in RFC 6108 https://tools.ietf.org/html/rfc6108, which has been in place for many years now. It presents an overlay service message on non-TLS-based HTTP sessions. If you click the X box or otherwise acknowledge the notice it should immediately go away. If that is not the case let me know and we'll have a look at what may be happening. [2]
But ultimately no, however there may be some possibilities:
- ISP offered 'apps'. Get people to agree to an install of some monitoring app for some [insert random marketing benefit] from ISP. Maybe if you install the app you get more data cap space etc and they can monitor browser access. Further, install this in known apps or as add-ons on setup for other apps.
- ISP offered 'VPN client' that again, gives some cheaper monetary benefit like more data cap space or more speed 'free', strips out other advertising or tracking as a benefit.
- ISP offered 'email client' that does all of the above.
- Check for subsequent request after page loads to known ad networks and replace with their own in HTTPS
- ISP level proxy MITM, modem customization for 'fast lanes' that are actually slow lanes.
- DNS level data collection not to inject but to sell marketing profiles via metadata and correlate with other data from apps.
First one is the most probable but as of right now HTTPS injection is obviously hard to do if not impossible without some social or security hole.
Nobody in here would probably fall for these attempts but most would considering the outrage that they didn't know friend harvesting was happening on Facebook. If whatever they try lowers their monthly data caps or limits then majority of people will do it.
Since ISPs are your 'gateway' to the internet and you pay them, most people assume trust and privacy, most don't know they bribed their way into the tracking/ad business, many didn't know cable tv modems had mics either. With that assumption of trust since people are paying them, they'll more easily fall for any of the possible attack/tracking vectors listed and more probably.
With the ISP privacy protections removed [3], my guess is most ISPs, due to lack of competition, end up more like hotel wifi where tracking/injection is the norm [4] as it is completely legal now. With the removal of privacy protections and net neutrality, we have killed the pristine, non tracked, private gateways to the internet we cherish.
[1] https://www.privateinternetaccess.com/blog/2016/12/comcast-s...
[2] http://forums.xfinity.com/t5/Customer-Service/Are-you-aware/...
[3] https://www.flake.senate.gov/public/index.cfm/2017/3/flake-i...
[4] https://medium.com/@nicklum/my-hotel-wifi-injects-ads-does-y...