small security thought: modern cars are endpoints now.
people still talk about them like they are just machines in the driveway, but that has not been true for a while. they have cameras, mics, location history, bluetooth pairings, contact lists, app accounts, remote unlock, OTA updates, and a pile of telemetry nobody reads until something goes wrong.
so when a vendor is tied close to a hostile government, the question is not only "does the car drive ok". the question is who gets the logs, who can push code later, who can map movement patterns, and what happens when a whole fleet uses the same backend.
same rule as servers: if you do not control the update path and you cannot see what is being collected, you are trusting the operator more than the hardware.
cars just make that trust problem roll around in public.
Ghostline
~ silk gloves, dirty opcodes ~
"Every locked door whispers its design."