I'm occasionally tempted to try building my own device, with a QWERTY keyboard, 320x240 monochrome LCD, and hardcoded apps for SMS and email. It would be big and clunky but it would be kind of nice to have a gadget that did exactly what I wanted.
I've learned that it helps to keep charging devices in one's carry-on bag.
Seems to me that in all of these cases, there is clear benefit to me and serves my needs as the end-user.
App permissions seem to be completely coarse-grained, and they all seem to need access to potentially huge amounts of personal data. I can't, so far as I know, disable their access to specific bits of data I don't want them to have; nor do I know of any mechanism for blacklisting or whitelisting access to specific internet hosts.
My Moto X decided a while back that it wanted to upgrade itself and started bringing up a nag screen at frequent intervals, interrupting whatever I was doing. There is no way I can discover to turn this off, and there is no way to decline the upgrade. It just kept nagging me, many times a day, for months. I can't disable this behavior; I can only choose between reduced functionality (getting interrupted mid-sentence and having to dismiss a dialog many times a day) or letting this remote server take over and install its software on my hardware.
In the end I feel like this device doesn't actually belong to me at all. It's more like a rental apartment: I can use it, and I can keep my stuff in it if I want to, but ultimately it belongs to the landlord; which in this case is a combination of Google, Motorola, and T-Mobile. The deal seems pretty clear: they get to decide what I am allowed to do with my phone, they get to decide where my information goes and who gets to see it, and I can either accept the deal or not use the phone. For the most part I have chosen the latter.
I think for most people, privacy is secondary to convenience and we basically sell data about ourselves in exchange for free use of these services that have become an essential part of our life.
I also think it's extremely hard to piece-meal control what permissions are allowed and requires substantially more work from app developers to consider all the possible conditional cases and have well thought out experiences when some/all pieces of data are missing. In many cases, it's just a matter of what is practical and doable in light of constrained resources. Not giving them a pass, but offering a possible reason instead of assuming malicious intent.
Presumably, the chief concerns are tracking and security. For instance, why does DropBox need to access my entire contact list just to backup my photos? Some people don't even think about it, others don't care but some do.
I think one of the challenges is that a lot of what an app maker wants to do is not known yet but they want to mine the user data to identify patterns that might help them decide on what features to build next or provide insight on how they should improve their app. Given this, they err on the side of asking for more data vs. less. On a mobile device, this definitely feels much more invasive given that our phones are basically "tied at the hip" when compared to classic web tracking techniques.
Knowing that "you" (your browser) looked at buying a car last week is far more valuable, especially when combined with other activity and demographic guesses. ie rather than a solid individual, your database records are a set of probabilities. Looked at diapers - probably have a kid. Looked at concert tickets for One Direction - you are likely young and very unlikely old. Combine all these anonymous snippets and probabilities and the database representation of you is then "exploited".
The goal is relevancy. Advertising pays on results, which means the advertisers don't want to pay for things going to people that aren't the targets. eg if they have a campaign aimed at females 20-30 years old that have children in North Texas, then they aren't going to pay for ads going to 60 year old men in Seattle. And if it is a car company, then ads going to people who are likely to buy a car in the near future is far more valuable than a kid playing Angry Birds. (There is also brand advertising where the idea is to keep a brand in your head and good feelings about it, but no immediate action expected of you. They find out if this works by doing it in some areas and not others, and then tracking sales etc over the longer term.)
In theory this should lead to you get good relevant to your interests advertising. In practise it is annoying drivel to many because the companies advertising (ie the ones paying) aren't relevant to you. They are trying to get your attention.
While I only mention advertising, the other pieces especially tracking are pretty much in support of the advertising. It allows the probabilistic deductions about you.
To avoid this you would need to eliminate Internet activity, or go completely anonymous (eg only using Tor, incognito browser sessions, and have components on your system constantly make up data like user agents and locations).
BTW you can see what Google has guessed about you at https://www.google.com/ads/preferences/ which works even if you aren't signed in.