I understand TBB aims to make everyone alike but HTTP_REFERER leaks all URLs you clicked from which is easy to track and correlate. Why is it disabled instead?
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Child items
0
Show closed items
No child items are currently assigned. Use child items to break down this issue into smaller parts.
Linked items
0
Link issues together to show that they're related.
Learn more.
While disabling HTTP_REFERER may be impractical due to some sites breaking, it would make sense to block it for links opened in new tabs. Most users likely expect that they won't be tracked to a new tab given the circuit isolation TBB has now.
Proposed patch for tor-browser to disable referer passing for links opened in new tabs: