Given the direction Google is moving in with passwords, this makes a lot of sense:
Their "on-device encryption" concept [1] seems to heavily lean on passwords as a client-side key entropy source, and preventing applications from sending that entropy source to a Google server every time they want to fetch emails etc. (and likely storing it not-too-securely in the process) is probably a good idea with that in mind.
App-specific passwords are a much better idea for applications like that; there's no need an IMAP client should ever store the same password that can potentially grant an attacker access to somebody's password manager or credit card auto-fill data.