Matthew Green pointed out something really interesting that I, at least, was unaware of. Apparently encryption libs do something breathtakingly stupid: They use the same random streams for a nonce (ie an attacker may see it) then immediately after use it for various other randomness needs within the protocol. So if there is any weakness in the random generation, you're exposing at least partial state of your random generator stream. Whereas if one used different random streams for the nonce and then other needs, you wouldn't be exposing as much state. Or at least that's my very non-expert takeaway.
edit: rsa not only uses a broken prng by default, but they appear to have actively aided the nsa.