It's talking about zone transfers. Normally clients will connect to your
DNS server and ask for specific information, like "Tell me what IP
address the host named 'www' has" (Eg, "host www.example.com"). Zone
transfers mean people can get access to hostnames and other DNS records
that you might consider somewhat secret, and don't publish in any other
way (Eg, "host -l example.com". Try it against a server that allows zone
transfers: "host -l pgp.net").

Normal DNS operation (with BIND) only requires zone transfers from the
primary server for the zone to the secondary servers, but no-one else
really needs them.

Of course, relying on "secret" hostnames is a form of security by
obscurity, and really isn't much like security at all. I've never
restricted zone transfers on any DNS servers that I've been in charge of
in the past.

Of course, there may be other concerns such as bandwidth use and
possible DoS attacks against a DNS server that allows zone transfers. I
don't know of any specific risks here though.
