TPM style solutions already exist. Keys burned into the chip + verification at boot should do most of the work.
> there must be some key floating around Tesla that can be used to completely reprogram any Model S from anywhere.
It could be something more interesting. A set of keys where signature requires N out of them? Even if there is some master key, they wouldn't keep it on a node connected to the network (one would hope...) Some hardware crypto-box maybe?