Oddbean new post about | logout
 Check out Cloudflare Zaraz; it injects the website with whatever content you like because they have the domain with them. (The NS)

Similarly, Ad and tracking agencies dynamically insert ads into the website without ever touching their main code.

It is https, but the certificate is not yours, and neither the origin server, they can insert whatever they like.