Earlier quoted context omitted.
They can't create trusted public keys after the fact, Of course they can. They own the directory server that hands out keys. http://blog.cryptographyengineering.com/2013/06/can-apple-re... tl;dr: Apple can send you a public key of Bob's new device. Apple can pretend to send you a public key of Bob's new device. And since it's proprietary software, they can trigger a resend of your recent messages to Bob. Moreover, if…
So this ends up being as "simple" as answering the question: Do you trust Apple? Given they control the operating system and all around it, having the directory server controlled by someone else (or distributed) doesn't solve the problem as they have access to anything they want in your device, meaning they don't need any keys to begin with.
You can reset your password and redownload all of your messages to a new device if you use iCloud backup. Cook is full of shit when he says that Apple doesn't have the capability. They own the system.
Even a dedicated civilian could reset your password, associate a device with your account and receive all messages going forward. To state that Apple cannot is such a laughable claim that it becomes clear that it's just a PR game. Which calls into question how sincere he is in his feelings about privacy.