Timing attacks aren't as simple as often presented. Writers often give a set time for checking each character and ignore all other operations in order to make the issue easy to understand, but most people use this to write off the attack altogether. Surely it can't be that simple.
It isn't trivial to take advantage of timing attacks remotely, but researchers have shown that they are definitely exploitable. [1][2]
[1] https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf [2] https://www.blackhat.com/docs/us-15/materials/us-15-Morgan-W...