No mixed content warnings here though. The ISP is editing the login page to include JavaScript that posts the password back, seemingly, to Facebook at Being a man in the middle, the ISP can capture all requests to this non existent URL and harvest the passwords. The browser can't suspect a thing.