The article author seems to ignore the existence of views. If you have confidential data query-able from the outside, it's a much bigger issue than wide open AXFR... Restricting AXFR is more cute than efficient, the information still leave your network unencrypted.
http://www.cyberciti.biz/faq/linux-unix-bind9-named-configur...