It is a way for the server to verify which username initiated a connection from the client by connecting back to the client on a privileged port and ask, referencing the local and remote port of the target connection.
There's definitely more to it than this, but keep in mind that djb was a teenager at the time, likely flaming for the sake of flaming as we all have at some point in our misguided youth, and no doubt, he was quite proud of his library.
I have some trouble guessing offhand what flavor of security confusion was fresh in mind from the preceding 3 to 10 years (and I was yet to be born), but after glancing at RFC 931, I'm going to guess that before this, user-hostname identifiers were handled in varied ad-hoc ways allowing spoofing of sender, or connecting user. I'm careful not to say "authenticating" user.
As best I can tell, it doesn't protect from MITM attacks. If so, I'm confused about what the point is.