What makes you think that the average user is better able to secure their own hosted system than a company with a dedicated team of security engineers can?
I'll suggest that fragmentation - not having a single point to find all user data would reduce the impact of a breach. Dropbox is a higher value target than John Doe. So hackers are probably less motivated. The user system itself may not be as secure, it may not need to be because a breach is isolated and an attacker would be less motivated.
Because of the honeypot effect. There is not much incentive for a hacker to hack an individual machine. he/she is better off targeting efforts towards sites like Dropbox. We saw the skydrive privacy breach yesterday. Before that we saw yahoo leak: http://www.readwriteweb.com/archives/yahoos-450-000-account-....
For instance, my employer IBM banned the use of dropbox in the company.