Please, don't use equality operator when comparing password hashes
nowhereref.com
nowhereref.com
Where it is important is cases where the attacker directly supplies the hash: e.g. protocols where the password hashing is done client-side, or HMACs securing tokens and things like that.
I wonder if there is any ecosystem that tries to nudge to this using the type system, e.g. having hash functions return a "HashString" type that will use constant-time comparison functions by default, and needs to be explicitly unwrapped if you want to turn it into a normal string type.