Earlier quoted context omitted.
> inject ads. If you believe that your ISP or a middleman can't inject ads without breaking the S in HTTPS, I have a bridge to sell you. They can just push the content into a frame and inject the content outside that frame. I encountered this more than once.
Unless the ISP forces the use of its own Certificate Authority on its users, this isn't possible. TLS and the infrastructure surrounding it were designed with integrity of the connection in mind. Knowing this, I would be very curious to know what specifically you encountered and where. I see you added some details elsewhere, but it still doesn't jive with how TLS works.
They're not doing this anymore, because I guess they now know how to use their DPI infra in useful ways to them.
My mobile carrier still injects stuff to HTTP pages, but doesn't mess with HTTPS ones, at least yet.