As someone who works on MQTT server technology, this opinion surprised me - it's a lot easier to get the security right using an MQTT server - user credentials are part of the protocol where as you have to build it yourself if you start at the TCP/UDP layer.
The problem in this example wasn't that they were using MQTT it's that there was no authentication/authorisation checking done - normally achieved by configuration - that would be possible in TCP as well - by not implementing it ;)