I think you may be misreading Apple's statement. The security of iMessage does not derive (solely) from PKI. Instead, the spokesman claims:
> There are certain categories of information which we do not provide to law enforcement or any other group because we choose not to retain it
Now it is up to you whether or not you take this statement at face value. But it's consistent with the other things I know about iMessage, as a person who has studied it in far more detail than your average HN reader, and so I believe it to be true.
If it is true, then Apple would be limited by technology to only provide iMessage dumps that started the date of the tap. If they did at all.
And I would be very surprised if they do at all. You obviously have to comply with a warrant to provide data if you have that data, but it becomes much more difficult, legally speaking, to compel somebody to collect information that they do not have to begin with. The CALEA was conceived to "correct" this "problem" but it only applies to "telecommunications infrastructure" organizations like ISPs, and courts have been reluctant to expand its application to actual internet services. It's something of an open secret that it was easier to simply acquire Skype for $8.5 bn and modify their technology than it was to obtain the necessary ruling under the CALEA that would compel them to modify it themselves.
Now if you are plotting revolutions, by all means, don't use iMessage. But my assessment is that the NSA threat level is lower than any other type of communication an ordinary person would be able to use, such as phone, e-mail, or even SSL.
Just as a point of comparison, DJB et al recently (2013) published a repeated plaintext attack on SSL/TLS that is viable at 2^24 TLS sessions. That sounds high enough to be safe, but if you consider the server case or the cron job case of rapidly opening SSL sessions, not so much. And attacks only get better. History suggests that the NSA is often a good ten or fifteen years ahead of the independent cryptographers, and meanwhile we are at plausible SSL attacks today.