Earlier quoted context omitted.
Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…
It isn't solved for computer networks, this is exactly the same as the current debate about secure boot. Secure boot is an open standard, but we've not agreed about who can hold the keys: http://www.fsf.org/campaigns/secure-boot-vs-restricted-boot Here, the EU has effectively said that someone with physical access to the car can generate their own keys (since anyone can pretend to be a mechanic, and all mechanics are…
I would disagree. To me this sounds like a perfect scenario for asymmetric encryption, which would solve this in a secure fashion.
Obviously someone should have a secure repository for official keys issued, so that duplicates can be made, upon request, upon owners' authorization. It might be bothersome and cumbersome, but the point is it should be a possible process, even for third party mechanical shops.
And for me the car-manufacturer sounds like a natural holder of this repo.
On the other hand, if you have access to the car and the key, it should be open enough to allow you to (re-)program it with your own keys if you like.
As far as I can see, that should satisfy everyone involved, while maintaining a secure architecture.