Without perfect forward secrecy. I'd probably take perfect forward secrecy over not needing a trusted third party for the protest use case, although neither is ideal.
It's easy to fetishize forward secrecy, but the reality is probably that forward secrecy is much more important in the context of TLS, where the lost of a single key might compromise billions of messages, than it is in the desktop case, where losing your key to an attacker also lost your keyboard inputs forever.
Or in a scenario where seizure of a device is likely incident to arrest (i.e. your mobile phone), or where the key is stored online, or where your key is derived from a passphrase.
Resistance to compelled disclosure (at least for historical stuff; they could still turn someone and force him to chat with people with an FBI agent watching over his shoulder...) is the benefit for PFS in the user to user case.