You still state in your updated post that: "The surprising aspect is that Authz has a validity of 300 days (which is likely to be increased)" [emphasis mine]. This would appear to be incorrect based on the source cited above , where it is stated at "Eventually, we'd like to make authorization objects much shorter than certificate lifetimes, probably 7 days."
Perhaps it's worth updating the post again in light of this?
https://community.letsencrypt.org/t/dns-authorization-lifeti...
It is from 14 June 2016 (a few months back), @pfg states "The CA/B Forum is currently developing new rules for domain validation and is probably going to settle on a validation period that is significantly longer than the 300 days currently in use ..."
Is there an authority to say which way it will go?
[1]: https://community.letsencrypt.org/t/upcoming-api-changes/179...
Token issues are something we solved about a decade ago. As to why LetsEncrypt has yet to learn these lessons, I leave that as an exercise to the readers and those familiar with security issues to discover for themselves.