Hypothetically, dropbox could install on the system a second, isolated authentication process, which generates a keypair for that machine, and hides it somewhere with an ACL that does not allow the normal user direct access. Then, upon login, the dropbox client asks the auth process to sign a nonce to login.
This would mitigate the problem to an extent; an attacker then wouldn't be able to succeed with just the user's data, they'd need to get administrative access to extract the authentication keypair as well. It would, however, require administrative access to install the authentication agent program, unless there's a suitable blind keystore in the OS already.