It is still possible to exploit a timing attack with a low resolution timer; it simply takes more samples. Meanwhile, people have managed to perform timing attacks (such as against OpenSSL) across a network (see the link below where I link to the seminal paper, "Remote Timkng Attacks are Practical"), as while the latency is large and variable it can still be trivially characterized. So, unless you are willing to apply a truly unpredictable delay function (some kind of Turing-complete noise which sometimes might block for arbitrary amounts of time) or, alternatively, a delay long enough to reauire the user to sit on the web page for "too long" (maybe weeks is the right calibration? I often find sketchy tabs that have been open for days) to essentially everything--and, in particular, all JS-initiated network requests--then you are likely just engaging in security theater by removing useful functionality from an API because it makes you feel more secure.