Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider serving Seattle, Bellevue, Everett, Lynnwood and Snohomish County businesses, founded in 2005, and multi-factor authentication is one of the most commonly recommended and most unevenly implemented controls in that work.
Multi-factor authentication is close to a necessity in any current cybersecurity plan, but not all MFA is created equal, and some of the most common options are genuinely risky. Here is how the methods actually rank, and why.
The great: hardware keys
Physical security keys, such as YubiKeys, Google’s Titan devices, or the token your bank may already issue, are the strongest tier available. They bind the login to the physical device and the specific site being logged into, which is exactly the property the weaker tiers below lack.
The good: code-generator apps
Authenticator apps such as Duo, Authy or Microsoft’s own MFA app run on a phone, which is more convenient than carrying a separate hardware key, and tie the code to that device rather than to a phone number. That is meaningfully better than the tier below, though it is not immune to every attack, which matters later in this post.
The ugly: codes by email or text
Codes delivered by email or SMS are the weakest tier, and the reasoning is worth spelling out rather than taking on faith. If an attacker already has access to your mailbox, by any mechanism, they also have access to every account that uses that mailbox for its recovery or second-factor codes. Using email to protect email-delivered codes is circular. Text messages fare no better: carrier-level SMS systems have themselves been breached, and cellular numbers are usually easy to trace once an attacker already has your email.
What made this concrete in 2021
In the fall of 2021, one clear illustration of the “ugly” tier’s weakness was the Autodiscover vulnerability disclosed that year: a flaw in the default protocol many email clients used to configure a mailbox automatically, which could be tricked into handing over network login credentials. That specific flaw was patched years ago and is not a live threat today. It is kept here only as a dated example of the underlying problem, not as a current risk.
The mechanism that replaced it
The specific vulnerability aged out; the reasoning behind the ranking did not, because the durable route to “an attacker has your mailbox” changed rather than disappeared. Two mechanisms do that work today. The first is infostealer malware, built to harvest saved credentials and session data from an infected device, feeding a marketplace of brokers who resell mailbox and account access rather than using it themselves. The second, and the more interesting one for this ranking, is the adversary-in-the-middle phishing kit: a proxy that sits between a victim and the real login page, capturing the session as it happens.
That second mechanism is worth naming specifically because it does not stop at email codes. It also defeats app-based codes, since it captures a live, already-authenticated session rather than guessing or intercepting a code in transit. That should strengthen this ranking rather than undermine it: hardware keys, which perform a cryptographic challenge tied to the actual site being visited, are the one tier a proxy sitting in the middle cannot successfully relay. The mechanism changed. Which tier survives it did not.
Executive summary: implement MFA everywhere, and for everyone’s sake, make sure it is the right kind.
Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.

