I might be revealing my stupidity here, but surely your ISP can MITM the HTTPS handshake and decrypt all of your traffic? Unless you have a pre-arranged key that hasn't travelled through their network.
The ISP can MITM the handshake and return a different certificate, but unless a certificate authority supported by your browser is complicit, they can't get that certificate signed for the domain you're trying to visit, and the browser will complain.
Unless they made it illegal to, I'm sure we'd see all the major browsers work to deprecate those certificate authorities pretty quickly - not doing so would make SSL useless.
What about the recent Comodo breaches? Their certs are still trusted by all major browsers (as far as I'm aware).
I realise they weren't complicit in issuing the fraudulent certs, but the effect is the same.