Sorry. You're right. I let the ultra dumbness of this whole thread bring me down a bit.
Doing an SSL MITM from agent software installed by the carrier on a phone seems pretty silly, since the carrier is in a position to see anything you're typing into your phone anyways (in the sense that it controls the OS).
I'm not sure I buy any analysis that suggests CarrierIQ is really "MITM'ing" SSL --- though that's trivial for a software agent to do --- because the same people saying that are also saying that it's obvious that CarrierIQ is capturing and remote-logging message contents.