Timing attacks aren't a flaw in memcmp or strcmp. Touching every byte of a string is stupid behavior in the overwhelming majority of cases.
Point your string function to a non-null terminated byte buffer for example. At the very least you can crash the app
What's recommended (one of the recommendations) is to use the 'n' functions like strncmp that takes a maximum size.
Using strncmp in this situation makes very little sense and is probably more dangerous. The lengths given to strncmp() are inevitably going to be derived from something else that requires a NUL terminator. Meanwhile, strncmp() leaves you open to logic flaws where you compare too few bytes.
Moral of the story, if you're going to use C strings, use the strn* variants.
If passed an unterminated string, the function will fail at least. How much you could exploit from that, I guess I exaggerated.
This whole subthread of picking on the guy's implementation because of "strcmp" is pretty silly. There are times where strcpy() is safe to use, but most of the time it's a red flag. There are conceivably times when strcmp() is unsafe to use, but to a professional reviewer, it is very rarely a red flag.
I should have just come right out and said that, rather than begging for the rationale for picking on strcmp().