Isn't this sent by the user's browser, and not by DDG? It's a client-side configuration issue -- turn off referrers in your browser. Your browser would send the same header if you clicked through a DDG search result.
Whatever happened to that 'mixed content' security warning, I thought that was pretty effective against stuff like this?
It's extraordinarily user-hostile, and would just add to the pile of pointless wankery that keeps people from using https (see also: shitting all over self-signed certs when in reality the CAs don't do shit for their rent and identity is useless anyway).
The actual solution is to never send Referer headers for cross-site requests from an HTTPS page.
That should be on someone's todo list at the major browser vendors. You're right, there really is no point in sending that header along, and sending it can cause all kinds of trouble.