The root of his concern is that Dropbox is vulnerable to local attackers. There is little Dropbox could reasonably do to meaningfully change this††. The Dropbox client needs to be able to authenticate itself to the Dropbox server as the price of entry to make Dropbox work. The Dropbox client is usually always running, and is in any case often running. While it's running, anything it did to prevent attackers from stealing authenticators could be circumvented by attacking the running Dropbox process.
If you think about it, this is a problem essentially shared by Google, and your bank. It is fair to critique the application for not making it even easier to revoke access to all but your current authorized machines (in other words, to make rekeying understandable and simple). But it's a UX issue, not a fundamental security problem.
† I may not; I'm going from 'trotsky's mirror.
†† Irony, based on previous comments from me today, noted.