Current cybersecurity standards enforced in the automotive industry will probably completely kill the possibility of after-market car parts and the usage of used parts in cars. I say this as someone working in this field that has asked a couple of people doing work in this exact direction. I point blank asked them if this will happen, and they just shrugged their shoulders and said... yeah, kinda'.
I also work in the industry and tend to agree. Right now if you get an official replacement ECU on a secured CAN network the device comes from the OEM already set up with the matching SecOC (AES-128) key that the OEM recorded in their backend database at time of manufacturing. But how would this work with a 3rd party ECU?
So far this has eluded public consciousness, but I expect it will hit the users hard at some point in the near future.