>> Just mixing in the time still has failure cases of nonce reuse.
> Really? Like what? I'd suggest you have a bad mixing algorithm in that
> case, or an actively hostile RNG.

like the battery is dead on your RTC, or you use nntp and the attacker can
adjust your clock, or get you to send messages across a leap second, etc.
