If you didn't revoke the application-specific password. And you should be revoking them when you're no longer using them.
If you weren't using application specific passwords, of course, it would have been your actual Google password in that Pidgin config.
It's a little disappointing that the app-specific password isn't more secure, but it's certainly not less secure than foregoing them.
App-specific passwords are bypasses of 2-factor auth. Use them selectively and with care, revoke ones you're not using anymore. And replace them from time to time.
Comments
If you didn't revoke the application-specific password. And you should be revoking them when you're no longer using them.
If you weren't using application specific passwords, of course, it would have been your actual Google password in that Pidgin config.
It's a little disappointing that the app-specific password isn't more secure, but it's certainly not less secure than foregoing them.
App-specific passwords are bypasses of 2-factor auth. Use them selectively and with care, revoke ones you're not using anymore. And replace them from time to time.