>> I'm an implementor, and I'm interested in implementing this feature.  :)
> It would fully break the basic use cases of Referer--being able to tell what
> server is inlining resources on your server and causing it to be hammered,
> and being able to do something about it.  "rel=originreferer" mode doesn't
> have that problem, though.

It's a matter of weighing the privacy and security benefits against
the costs to that use case.  If you're interested in that use case,
you might be interested in Anne's From-Origin proposal, which
addresses it head-on.

(BTW, I don't agree that use case is "the" basic use case for Referer,
but that's a matter of opinion.)

> By the way, does this need to consider CORS and the Origin header for <img
> cross-origin>?  I'm not fresh on how that works.

Nope.  The two do not interact.


