It's the typical security vs accessibility trade-offs. Accessibility won.
It's the typical security vs accessibility trade-offs. Accessibility won.
Two-factor is a pain on iOS devices where every Google app needs it's own unique password and frequently need a new one for every update. Android is a completely different story though and adds almost zero overhead.
Now, you've got several passwords that work, instead of 1 and a keyfob. Ugh.
Edit: Apparently, you can't log into the web interface with those passwords. That's a step in the right direction, but still not fully secure.
They are strictly better than using a single password for everything though, in that they are unique and strong (due to being automatically generated and 16 characters long), and easily revocable.
I suppose there is one possible negative consequence to users who opt not to use app-specific passwords: their existence alone removes some of the incentive for client applications to implement 2-factor themselves (which I don't know if Google even has an API for). And sure, it would be nice to have features like access control on a per password basis (e.g., so I could allow Pidgin to access only gchat, but no other part of my account). But the implication that the mere existence of application-specific passwords somehow makes Google's 2 factor auth useless is just wrong.