@BeAware It's like when you log in to your Mastodon/Fedi account in an app, you're shown your server's login page in a browser and then "Do you want to authorize app X to do Y?" and you press "Authorize". And in Bluesky/ATProto at the moment you enter that "app password" at the moment to log in, you give the app password to the third party app itself instead of to your server's login form. It's less secure because they get that password itself instead of a token & they get access to whole acct.