The situation is worse than CAs with conflicts of interest and hacked CAs: if a CA sets out to do bad stuff it can pretty much go ahead and do it. By the time the act is discovered and certificates revoked millions or billions may have been stolen or people locked up, tortured or dead (think bad govt. controlled CA).
Trustwave has just been caught with its pants down on this (http://www.h-online.com/security/news/item/Trustwave-issued-a-man-in-the-middle-certificate-1429982.html) but naturally they are claiming that they only did it with good in mind and nothing could possibly have gone wrong, but they say(!) they won't do it again anyway.
Yup, I'm reassured too!