(1) You can do the attack you describe today with existing CAs that are issuing DV certs because posting a file on the web server is an existing DV validation method that's in routine use.
(2) There is another validation method we've developed called dvsni which is stronger in some respects (but yes, it still trusts DNS).
(3) We're expecting to do multipath testing of the proof of site ownership to make MITM attacks harder. (But as with much existing DV in general, someone who can completely compromise DNS can cause misissuance.)
(4) If the community finds solutions that make any step of this process stronger, Let's Encrypt will presumably adopt them.