> djb has mostly convinced me

You might check out his thoughts in the XSalsa20 paper:


"There is also a standard counterargument. Counters might sound simple but
are sometimes mismanaged by applications, destroying security. Rather than
blaming the application for this failure, we can append random bits to the
adding protection that is likely to succeed even if the counter fails."

Combining counters and RNG data was one of the reasons he created XSalsa20
in the first place.

