I don't think this part is true. There are constant time software implementations of AES: https://crypto.stackexchange.com/a/92/21442
(Designing easier-to-implement-securely algorithms does help.)