If you don't mind, I'd like to add to your blog post.
Token issues are something we solved about a decade ago. As to why LetsEncrypt has yet to learn these lessons, I leave that as an exercise to the readers and those familiar with security issues to discover for themselves.