Why would you even worry about it not being a joke? Even if by some quirk of fate they were serious, the code would immediately fail and put no data at risk.
No, this is totally insecure. You're supposed to generate a public/private key pair for the user, encrypt the hash with the public key and store the private key in a separate database on a separate server that isn't connected to the internet and doesn't allow remote log-in from the lan.