Earlier quoted context omitted.
Why do you use the term 'application-specific passwords' although these passwords are not application-specific at all? They are Google-generated passwords with a user label. And if you use 2-factor authentication, they are the weakest link in the chain since they provide full access to a google account except for access vectors with 2-factor authentication. In addition, every app can use such a password, not just the…
Application-specific is just a friendly name. Also this password doesn't give you full access to your Google account. You cannot log into Google web apps this way (AFAIR). Thus you won't be able to mess with account settings (passwords etc). Before you can change critical account settings Google asks you to provide your traditional password again. Your comment is a bit harsh if not FUD.
Using one of these so-called application-specific passwords, you can delete calendars, mails and contacts. That is critical enough for most users.
An additional concern is the usual 30-day authorization you give in order to avoid entering your 2-factor token again and again. Is there any way to de-authorize such a 30-day authorization?
Anyway, I don't rule out that my perspective might be too strict. For must users, the whole Google 2-step authentication system is probably a very important step towards improved security.