This is categorically not true. The only way end-to-end HTTPS can be decrypted is when the signing certificate has been replaced, which might happen if you're using a computer which you do not own (eg internet cafe). If someone tries to decrypt the traffic with an unknown certificate, you get a big fat warning in the browser.