I wonder if this can be socially engineered/tricked to gain a certificate for someone else's domain. Like, I've seen at least one service (Majestic Seo) that asks you to upload a document to your domain to get certain services. Now that this (will soon) exist, any such service that someone uses can generate a cert and MITM the site.
Also, if they're verifying over http, couldn't anyone just mitm the verify connection? Well, anyone with access to any computer along the route between Let's Encrypt and whatever domain they want.