Vodafone.pt is rewriting CSP headers to whitelist Vodafone and jQuery
twitter.com
twitter.com
I was in Portugal last summer, and my family had a Vodafone 3G wifi hotspot. I noticed that on every single non-https webpage, Vodafone was inserting a banner with a huge load of JS, as part of their "Vodafone Secure Net" "feature"(https://securenet.vodafone.com/). They inserted their own code on every request to make sure that they could display a banner telling you whether or not a website was "trustworthy".
I managed to figure out the complicated steps to do on their systems to turn this "feature" off, but between that and some other bad experiences I've had with them I still don't trust them in the least.
https://www.telegraph.co.uk/technology/news/8438461/BT-and-P...
https://electrospaces.blogspot.co.uk/2014/11/incenser-or-how...
To top it all off they also block all SMS access to twitter and instagram. Hope someone takes them to court ASAP
Ignoring the corporate speak, they admit they do for censorship reasons.
[0] https://twitter.com/VodafonePT/status/968544082707603456
Furthermore, MITM is either in exchange for something of value and therefore desired by the user (regulatory compliance at work, perhaps free wifi at coffee shops, perhaps better performance for older cellular networks), or it is an attack. The existence of MITM in general is not normal. Why should Vodafone be MITMing at all? Why is "as attacks go, I've seen worse" a defense?
then there's net neutrality.
I wasn't arguing for MITM, I was arguing that it's not any worse than your run of the mill MITM