ParentFull threadadn37·Attacker sits at network / ISP level, and can therefore inject any (js, ...) payload in non-https web pages, on the fly.View on HN