Upon further reflection, the question is "how hard is it to find the needle in the haystack"
If you use a 128 bit key, but use a non-time-constant compare somewhere, then it's pretty darn easy to find the needle.
This is why the JPEG fingerprinting example from TFA doesn't qualify to be in the same category as a properly secured cryptographic key. They can notice that non-picture posts are not blocked, but picture posts are, which already greatly narrows it down. They could post a picture generated from the actual client, and see it go through, and narrow it down even more. That's not even that hard of a one for an attacker to figure out. It's much closer to "key under doormat" than "random key"