> The current specifications allow phones to learn when and where they were in contact with another device.
That's over simplifying it massively. First the spec clearly states that no location data is recorded, since the location is not necessary for the application of contact tracing.
> By pushing a button on one phone, by reporting it as infected, all other phones that were recently in close proximity reveal themselves to the central server
This is not true, they clearly state that matches with a Diagnosis key is not uploaded to the diagnosis server.
> The current specifications allow phones to learn when and where they were in contact with another device. It is unclear whether the actual identity of that device is also revealed.
This is just not true, they make it abundantly clear in their specifications, that the identity of the device is never revealed.
> A company could install Bluetooth beacons equipped with this software at locations of interest (e.g. shopping malls). By reporting a particular beacon as ‘infected’ all phones (that have been lured into installing a loyalty app or that somehow have the SDK of the company embedded in some of the apps they use) will report that they were in the area.
This is not how this works, this is not how any of this works! It is highly speculative and extremely unlikely that any random APP will have access to the tracing key to make that even remotely plausible.
This criticism is obviously written by somebody who has not read the specification[1] or did not understood key aspects of it.