Apparently Satoshi had never read page 35 of the Standards for efficient cryptography, SEC 1: Elliptic Curve Cryptography published on 2009 on Symmetric Encryption Schemes before writing this wrong reply

Unfortunately, ECDSA can only sign signatures, it can't encrypt messages, and we need the small size of ECDSA.
Post
#15 (slightly modified below)
It could use a separate infrastructure to pass messages, maybe just put a hash of the message in the transaction to prove that the transaction is for the order described in the message.
I.E. Side Chain.