Earlier quoted context omitted.
HTTPS will keep out injection during transit from the server to your computer. But it will do absolutely nothing against toolbars and other browser extensions and that is what this article is about so at a guess the 5% is on top of injection in transit.
Why does the browser even allow any toolbar/extension to modify the content that was delivered on a HTTPS connection. Isn't the data that is delivered over HTTPS pristine that it should not be modified at the browser endpoint by the browser. I am a layman in security and do not understand a lot of this. May be I missed something here. Is my question correct?
You're probably reading this page using https and there are quite a few extensions to modify the look and feel of hackernews.
Changing on-page content is just about the only reason extensions exist in the first place. Without that you could retire just about all of them.