Thinking about ad injection, it is actually quite scary what a ISP can do. Not only is it easy to display ads (or possibly even malware), but even worse my ISP is installed as a default CA by Firefox. So that they can even inject into SSL connections, with the only "warning" that the certificate was signed by the ISP...
Telekom ( actually T-Online, the German ISP branch). The certificate is identified as T-Systems (and I just found another one, Deutsche Telekom AG). Additionally looking through the certificates I found at least Swisscom who appear to have both a CA and an ISP, and AOL. But this is certainly not an exhaustive list but just the ones that caught my eye scrolling through the list of CAs.
[EDIT]And for the added 'told you so,' the German parliament uses precisely this certificate https://www.bundestag.de/
> This CA was singled out as a CA that signed an excessive number of intermediate authorities (252) which together only have issued 4164 certificates in EFFs talk at C3. This is, by far, the highest number, the next contender is GTE Cybertrust with 93.
The bugzilla thread is an interesting read. And to be fair, the issue with the thousands of certificates is explained in it. It appears that the certificate is used to sign DFN, which in turn signs certificates for most German universities.
Well, you can at least remove those from the trusted cert list manually, but it seems like insanely bad juju for ISPs to have their CAs installed with the browser. I wonder if that's worth opening a bug on the Firefox tracker.