I agree with you that there is some theater, that is why I wrote this article. This tool allows you "yourself" to determine what the app is doing. I have been researching this for over a year and the only other method I know is to reverse-engineer the code. In the near future, a research team from Germany that I interviewed will have another tool:
http://www.techrepublic.com/blog/security/android-apps-and-ssl-wheres-the-padlock/8836?tag=content;blog-list-river