http://tools.ietf.org/html/draft-rescorla-tls-extended-rando...
(The first seems to be "Opaque PRF Inputs for TLS" from December 2006. http://tools.ietf.org/html/draft-rescorla-tls-opaque-prf-inp... so the process lasted more than two years)
The relevant parts from the last:
TLS [I-D.ietf-tls-rfc4346-bis] and DTLS [RFC4347] use a 32-byte
"Random" value consisting of a 32-bit time value time and 28 randomly
generated bytes:
struct {
uint32 gmt_unix_time;
opaque random_bytes[28];
} Random;
The United States Department of Defense has requested a TLS mode
which allows the use of longer public randomness values for use with
high security level cipher suites like those specified in Suite B
[I-D.rescorla-tls-suiteb].
This document defines a new TLS extension called "extended_random".
The "extended_random" extension carried in a new TLS extension called
"ExtendedRandom".
struct {
opaque extended_random_value<0..2^16-1>;
} ExtendedRandom;
Note how they used the notation that casually looks smaller as in "there's 2 and 16 and 1" when they actually mean up to 65535 bytes (I've first thought it's fixed but it looks the length is a subject of negotiation).Roughly 2300 times more than the default 28 bytes.
TPtacek says: "It's now thought to be risky to disclose too much state. But that was definitely not the attitude in place in the early 2000s --- more randomness was better."
I can't imagine that there was ever an attitude that it's not risky "to disclose too much state."