"The attack can't use external input e.g. clock because the NSA can't correlate generating the random number with seeing it in flight."
It could potentially use the number of milliseconds since the last hour, or maybe the state of the branch predictor, or any number of other things that have exploitable biases (with NSA resources, 1/1000000000 is pretty good odds).