Not entirely clear why you are posting this?
It's clear that there is some diversity of opinions on this topic, but we already knew that.
To me, your datapoint shows that Dropbox is right to behave the way they do: in 2011 you thought it was high risk, they have kept with that behavior and yet nothing bad has happened. I'm unsure if that was your intention, but that is how it looks to me.
It is entirely unclear why you think this is particularly risky: If Dropbox can do it, then other malicious programs can too.
Dropbox's behavior creates no additional security risk, but increases the usability of their software.
If there really is a security problem here, then surely that is a problem with the OS, not Dropbox, and it is the OS that should be fixed?