Earlier quoted context omitted.
Google's 2 step authentication is completely useless to some of us because they don't have actual per application passwords. For example if you use an IMAP client to read gmail, then you can get an "application specific" password for it. But Google then allow that password to be used for anything. Essentially you've used 2 step authentication in order to setup 1 step authentication.
Yes, but they must first guess that password (which is ostensibly longer and more random than the typical passwords people choose.
My chat client, IMAP client etc all save the password. Guessing the password is the least likely avenue of attack.