>You don't need to backdoor the protocol, just the specific targeted client.
So how are you backdooring the client that -- where ever you download it from -- can be dumped from the phone and compared against self compiled client with a cryptographic hash?
Introducing intentional, ubiquitous vulnerabilities is also a terrible idea, because exploits for those can leak or be stolen (that has already happened, see Shadow Brokers case), and that's catastrophic in operating systems, because they're massively scalable.
Rootkits injected via such vulnerabilities can covertly make systems so that the vulnerability and backdoor are unpatchable, and that would be a catastrophic scenario.
>Signal can scan messages before encryption and report to the authorities just fine
Writing a script that comments out the lines of code for such scanning, and that compiles the application from source is trivial.
People write E2EE layers on top of existing messaging apps. One example is OTR plugin for Pidgin/Gaim, another is CryptoCat that at one point had a system that operated on top of Facebook web UI.
The genie is out of the bottle, and the bad guys are willing to go the distance to get secure comms. Bin Laden was using airgaps. Criminals are buying crypto phones (that ANOM case was fun example of smart targeted attack though, maybe that can be used to catch some criminals in future too). What's left is the security of normal people from banana dictatorships, mass surveillance tools etc. When you backdoor privacy tools, that's who you'll get, and if that's who you're going after, then you have no right to wield such power.