The real kicker is that he tries to justify it by saying a sql injection attack would prevent the attacker from getting passwords. If you're seriously worried about sql injection, inventing a retarded password scheme seems like a secondary worry to revising your coding standards to require prepared statements.
Treating any part of a user password scheme as secret is doing it wrong. This is why bcrypt exists.