It's more scary if they've compromised a SSL CA. A simple DNS attack won't stop your browser from displaying a broken certificate warning. (Though they can always not redirect from http to https and most users won't notice, sadly.)
it's very easy to get your own https cert once you control the dns for a domain, you just set up own nameserver that proxies requests to the original NS (except very specific ones, say those from Verisign), request your "domain control validation" https cert, and bam! valid https cert!
It said "not redirect from http to https" -- meaning that when someone requests http://example.com they would normally be redirected by the site owner to https://example.com, but the attacker could just leave the original request alone. The point is that most people wouldn't notice.
HTTPS Everywhere or similar browser plugin would probably pop up an alert if this did happen.