The issue is that iMessage outright ignores a long understood challenge in the APPLICATION of cryptography, namely knowing when to trust that someone is REALLY giving you their public key rather than being man-in-the-middled.
While this is a thorny challenge there are well understood, if imperfect, ways of addressing it that have been around for decades. At minimum it works like ssh, where you get a warning when an unfamiliar new key is presented and decide whether to trust it or not. More sophisticated is the certificate infrastructure around TLS/SSL where some effort is made to bring semi-trusted third parties into play.
These are all flawed solutions, the problem remains essentially unsolved. But any truly secure system based around public keys has some mechanism that addresses this challenge.
The issue with iMessage is that 1. Apple did not attempt to address the key exchange problem, which would maybe be fair enough on an "easy" consumer product with weak security claims but then 2. Apple made strong security claims very publicly and 3. even said a counterfactual, that it had no capability to intercept messages.
THAT is what is disingenuous: Apple implements public key cryptography, which since its inception and at its very heart raises difficult challenges around key exchange; Apple chooses to ignore these challenges; Apple then claims strong public key security. Either attempt to address the challenges like everyone else, or don't make the security claim, you can't do both.