I understand TBB aims to make everyone alike but HTTP_REFERER leaks all URLs you clicked from which is easy to track and correlate. Why is it disabled instead?
Designs
Child items
...
Show closed items
Linked items
0
Link issues together to show that they're related.
Learn more.
While disabling HTTP_REFERER may be impractical due to some sites breaking, it would make sense to block it for links opened in new tabs. Most users likely expect that they won't be tracked to a new tab given the circuit isolation TBB has now.
Proposed patch for tor-browser to disable referer passing for links opened in new tabs: