"...almost all of whom are running TLS internally and have significant, security-critical investments in out-of-band TLS decryption. Like many enterprises, financial institutions depend upon the ability to decrypt TLS traffic to implement data loss protection, intrusion detection and prevention, malware detection, packet capture and analysis, and DDoS mitigation. Unlike some other businesses, financial institutions a…
The argument here could be whether you, as an individual working for an employer on employer-controlled hardware, have the right to communications that cannot be viewed by the employer at their discretion on those systems.
Having that capability (undecryptable communication) on an exceptional basis (e.g. only a few sites or methods do it) might be grounds for blocking any instances of the protocol that negotiate that level at the border.
Having every secure site do it would result in not being able to passively store and only decode the communications that, say, you have occasion to go inspect later for discovery reasons, and instead would require MITMing and downgrading all connections (and storing the traffic, at best, re-encrypted with a different key).
(Note that I'm not voicing an opinion on the topic, just observing that there are legitimate reasons to desire this functionality from several perspectives, which do not necessarily imply wanting a backdoor in the protocol in the general case.)