Application-specific passwords weaken Google's two-factor authentication, researchers say

Researchers discovered a loophole in Google's authentication system that allowed them to bypass the company's 2-step login verification by abusing the unique passwords used for individual applications.