You're at risk from the US government, but it's unclear that a government that can compel Dropbox to hand over your database and then crack some pretty heavy encryption can't access the accounts you're protecting with those passwords in some other way.
The main adversaries, IMO, you're protecting against are non-government actors, and your setup should be completely adequate for those.
FWIW, I have the same setup, but with Keepass.
http://www.theatlanticwire.com/technology/2013/06/prism-comp...
The safest option is to prevent 3rd parties from having access to your encrypted data in the first place. This is the approach Bluepass is taking.
Obviously the token file would be something you don't put into cloud but instead store on each physical device.
"What are you protecting,"
Freedom
"and who are you protecting it against?"
The US(UK) government.
The US / UK have imprisoned people without charge, trial or conviction, and based on flimsy evidence. Some of those people will have been tortured.
Feel free to suggest 1password on dropbox, or Bluepass, if you think either of them can protect against well funded government agencies. I hope you're also recommending better door locks, no windows on the ground floor, 5 metre fences, hardened computer running hardened OS, etc.