Earlier quoted context omitted.
If I'd be Google - I'd force senders to have 2-step authentication configured before sending money.
Google's 2 step authentication is completely useless to some of us because they don't have actual per application passwords. For example if you use an IMAP client to read gmail, then you can get an "application specific" password for it. But Google then allow that password to be used for anything. Essentially you've used 2 step authentication in order to setup 1 step authentication.
App-specific passwords are one-factor in any case (they are "something you know" just like any other password), and are an alternative to two-factor auth for certain places where Google's two-factor auth isn't supported for one reason or another. Google's 2-factor auth requires a device (usually, smartphone app) generated code alongside your regular Google password.