Can anyone explain what exactly is meant by "SSL added and removed here! :-)"?
My interpretation is that they've acquired - either via bag job or by unpublished algorithm - Google private keys, and are decrypting and copying traffic immediately before the Google Front End, then impersonating the client to the Google Front End. Presumably, the Google Front End is on Google premises, and Google would be aware of the warrant that let NSA install such a device behind the Google Front End, whereas the peering point in front of the Google Front End (or on the fiber to the Google Front End) would be on Telco premises, and we've seen the Telco's be all to eager to cooperate. Oh, except Qwest, where the CEO found himself in jail.