Seems to me that in all of these cases, there is clear benefit to me and serves my needs as the end-user.
Seems to me that in all of these cases, there is clear benefit to me and serves my needs as the end-user.
App permissions seem to be completely coarse-grained, and they all seem to need access to potentially huge amounts of personal data. I can't, so far as I know, disable their access to specific bits of data I don't want them to have; nor do I know of any mechanism for blacklisting or whitelisting access to specific internet hosts.
My Moto X decided a while back that it wanted to upgrade itself and started bringing up a nag screen at frequent intervals, interrupting whatever I was doing. There is no way I can discover to turn this off, and there is no way to decline the upgrade. It just kept nagging me, many times a day, for months. I can't disable this behavior; I can only choose between reduced functionality (getting interrupted mid-sentence and having to dismiss a dialog many times a day) or letting this remote server take over and install its software on my hardware.
In the end I feel like this device doesn't actually belong to me at all. It's more like a rental apartment: I can use it, and I can keep my stuff in it if I want to, but ultimately it belongs to the landlord; which in this case is a combination of Google, Motorola, and T-Mobile. The deal seems pretty clear: they get to decide what I am allowed to do with my phone, they get to decide where my information goes and who gets to see it, and I can either accept the deal or not use the phone. For the most part I have chosen the latter.
I think for most people, privacy is secondary to convenience and we basically sell data about ourselves in exchange for free use of these services that have become an essential part of our life.
I also think it's extremely hard to piece-meal control what permissions are allowed and requires substantially more work from app developers to consider all the possible conditional cases and have well thought out experiences when some/all pieces of data are missing. In many cases, it's just a matter of what is practical and doable in light of constrained resources. Not giving them a pass, but offering a possible reason instead of assuming malicious intent.
Presumably, the chief concerns are tracking and security. For instance, why does DropBox need to access my entire contact list just to backup my photos? Some people don't even think about it, others don't care but some do.
I think one of the challenges is that a lot of what an app maker wants to do is not known yet but they want to mine the user data to identify patterns that might help them decide on what features to build next or provide insight on how they should improve their app. Given this, they err on the side of asking for more data vs. less. On a mobile device, this definitely feels much more invasive given that our phones are basically "tied at the hip" when compared to classic web tracking techniques.