Beating Google Two-Factor Authentication with App Specific Passwords.
l8security.com
l8security.com
http://www.rodneybeede.com/Protecting_against_MITM_and_sslst...
Surely the fix from Google would be pretty simple? Just make sure that any and all access to the 'Two Factor Authentication Settings' page required a two factor token. I thought it already did, but I've just tried it and the OP is right, you just need a password.
But even if we assume that Alice is totally hosed once Bob completes a MITM attack, I think you're right that there needs to be two-factor auth to create an app-specific password. It wouldn't protect from MITM, but it would protect from watching over Alice's shoulder, keyloggers, and all sorts of other ways that Bob might get Alice's password without being MITM.
(Edit: Google does require two-factor auth to access www.google.com/account and generate new app-specific passwords, doesn't it? I thought it didn't when I first tried, but that's just because I've already authorized this computer. If that's the case, then I'm inclined to believe that Google has done all it can do. If an attacker controls your secure communications with Google's server, you are out of luck period. If an attacker only has your password, then two-factor auth will keep them out of your email like it's supposed to.)
As far as Google's control extends, I can't think of anything they could implement without flaws that wouldn't be hostile to most of their end users.
If it weren't this flaw, it'd be a "zomg, I can plug a USB key into Alice's computer and install a keylogger".
This is a trivial, routine style of attack and of course it will work against Google's security scheme which is catered towards the everyday Joe and Alice and designed more to protect against phishing.
A better scheme where if you lost your phone, you lose your data forever, would not pass muster with everyday users.