I used to work at a telco and we absolutely knew your location based off base station triangulation. And we knew who you called and messaged and who was nearby to you.
i.e. most folks in favor of GACT adoption see the alternative path, of using actual location data without opt in and operated by the government, as a scarier erosion of privacy.
You cannot use this system to determine if two people have been in contact. It doesn’t have the capability.
All you can tell is if one person who explicitly participates in the system has had contact with one or more of any of the other people who explicitly participate in the system who indicates they are infected, but not which people.
My understanding is that given someone else's daily key, it can tell you whether you were in contact with that specific key.
So anonymity relies on not knowing who had that key. But the (as yet unspecified) authority collecting "infected" keys will certainly know who submitted what, so you are relying on their secrecy.
If you assume a malicious app installed on both party’s phones, then you might be able to do it... but then again, if you have that you don’t really need this system to track contacts.
(I think on one side, you’d have to collect the daily keys and associate them when a person’s identity. Then, when you want to check a contact, you would then need to trigger an “infection” because otherwise the keys don’t leave the device. This requires user interaction, BTW, so there would be some kind of special social engineering effort to get someone to report themself as infected or else you the phone needs to be unlocked in the possession of a malicious party — or you have to hope to get “lucky” in that the person actually gets infected within 14 days of the timeframe of interest.
For the other party, you’d have to feed only the specific ids of the known people you want to check against to the matching API — it only tells you if there’s a match, not which match, so unless you’re checking only one, you’d have to use a process of elimination to work it down to a specific person. I wonder if that API might be throttled, though, or otherwise limited to make that less effective.
With the requirement to have malicious, cooperating apps on both sides you don’t need the Apple/Google system and you could get more useful info, like location, and with less user interaction.)
Also, the Apple implementation requires user to manually approve access to user private tokens each and every time for apps trying to access them.