Thanks for the explanation, and sorry, I still am lacking a good model for what is going on.
You only have to enter them once because most clients nowadays provide a 'Remember my Password' functionality. Google assumes you will use this, so only need to enter your password once
Is this really true? Because the documentation for the one time auth doesn't indicate anything like that.
So I am confused as to what is happening in the background on Google's side.
My pseudo-model is that their password acceptance library looks for a correctly identified two factor authentication OR a one time password out of the user's one time password table.
But then I don't understand why these one time auths are one time! If someone finds my phone, or accesses one of my other net accounts that was authorized by my one time auth, they completely win until I can get back to google's page to revoke them.
And related, I don't understand why the authenticator can't generate these one time passwords -- MANY TIMES THAT WOULD BE A LOT MORE CONVENIENT than having to go to the specific page on the web.
And also related: why is there no pin or password for the authenticator?
These are just questions I have -- I'd love to read a page or two that discusses these issues -- I think having a good model of how and why it works as it does would help me secure my data.