Isn't the actual content of the page signed by the the site's certificate though? And they can't just serve a different certificate because your browser can tell whether or not it was issued by a trusted CA. How does the attack work in this case?
Edit: Nevermind — I assume you're referring to this scenario[1], in which the company installs a root certificate onto your actual computer that allows them to sign certificates for other sites.