What sensitive metadata was unintentionally exposed in Google's private implementation?

Answer

IP addresses

Although the Exposure Notification (EN) system, including Google's component, was designed with the core tenet of privacy, relying on rotating cryptographic keys instead of GPS location, a significant practical oversight was discovered during implementation. It was found that certain features integrated to maintain compatibility with centralized systems inadvertently allowed for the transmission of IP addresses. Since IP addresses can often be used to infer geographical location, this revelation demonstrated a practical gap between the system's decentralized design philosophy and the realities of integrating it with potentially more invasive infrastructures favored by local health agencies.

What sensitive metadata was unintentionally exposed in Google's private implementation?
inventiontechnologyappcontact tracingdigital health