I once found a bad implementation of this idea in a common commercial crypto library. I calculated from observation of a bunch of runs that they were achieving about 45 bits of entropy in practice, and taking six seconds of wall time and a shitload of power in the process.