Also, the fact that apps only auto-update when the permissions required don't change produces all the incentive for app developers to just ask for everything. After all, most conscious users will find something they object to at install time anyways and thus might not install and most people don't read the dialog anyways, so not much to lose.
But even when android changes to ask for permissions as they are required (which could be done in a backwards compatible way by not throwing exceptions but just pretending that whatever API call you just made has succeeded, but then doing mothing or returning meaningless/no data), this still would not help with a malicious app asking nicely with a legitimate reason ("let me access your SMS to read the login token") and then using that permission for illegitimate uses ("let me upload all your SMS to my server").
Even with all these permissions, it still boils down to trust and where on the desktop world, this trust was rarely abused, in the mobile world between all the built-in adware and social integrations, that trust is badly hurt.