I have to assume by "hardware authentication key" they're referring to RSA SecurID. Yubikey would indeed prevent an attack like this from working.
Although I wouldn't expect a company like Dropbox to be using RSA SecurID.
Although I wouldn't expect a company like Dropbox to be using RSA SecurID.
It would using U2F / WebAuthn. Some Yubikeys support generating TOTP codes [0], which would be vulnerable to phishing attacks
[0] https://support.yubico.com/hc/en-us/articles/360013789259-Us...