Right now they have a system where automakers granted themselves a dangerous and unreasonable level of remote access to cars that aren't theirs. Now they're claiming that it would be dangerous and unreasonable for third parties to have that level of remote access to cars that aren't theirs.
No kidding.
But you could easily have a system where a remote access server has to be authorized by the owner, e.g. by having to press a button inside the car while the key is present. And could be revoked by the owner in the same way. Then the car could be repaired by anyone... who is inside the car and has the key. Which is not only completely reasonable, it's more reasonable than the thing they're doing now.
Some car manufacturers have also attempted to use encryption and implemented it so poorly that it was easily cracked.
There is no technical reason that a car key can't effectively be a yubikey. The computer issues a challenge to the key, answering the challenge requires a secret stored in the key, so you need the key. It works as long as the encryption isn't broken.
And if "car can be remotely controlled" and the encryption is broken then that's a much bigger problem than anything your local mechanic is doing.
This is how most modern “smart key” systems work.