On Android there are very granular permissions, and an application cannot do anything -- like getting your coarse or fine position -- that it wasn't specifically granted rights to, however like the article mentions it's hardly difficult to social engineer an explanation for why the right should exist. And of course, sometimes benign apps do need far reaching rights in a way that causes user security fatigue. Barcode Scanner, for instance, scans barcodes and looks up products, yet on install it demands -- all or nothing -- that it have access to your contacts. That concerned me greatly, but I later learned that it can also generate barcodes for your contacts.
Android security can be improved. For instance apps should have optional right requests. I would say no to contacts on Barcode Scanner, for instance, and it should live without that right, just as I would say "no" to a game where I don't use geolocation matching for if it wants positional data. There should also be the option for an "on use" right setting, where, for instance, whenever it asks for my fine position I have to individually grant that right, which is the one thing that iOS does right.
This is ultimately simply an installer issue -- the reality is that apps already can probe to see if a given right is available, and can enable/disable functionality based upon it. All that is needed is for the installer to provide the boolean.
Overall, though, I feel far more secure with the granular permissions model of Android than with the all-or-nothing (aside from fine position) iOS model.