But overall I'm all for getting rid of it. It's a remnant of the early web that doesn't make a lot of sense these days, and creates more problems than it solves.
EDIT: Although I just realized that strict-origin-when-cross-origin (the new policy) would still let the hotlinking detection use case work, since you typically only need domain information for that. I initially thought that they would use same-origin or something like that. It'll teach me to comment before I read the linked story.
Using the referrer header as a security and privacy measure is prevalent among service providers. Vimeo even hilariously charges for this feature which is trivially bypassed; and I'd reckon their paying customers aren't even aware of it: https://vimeo.zendesk.com/hc/en-us/articles/224819527-Changi...
Talk about smoke and mirrors.
How can you tell it's Monday morning on HN?
Someone starts pontificating, "I don't use this, so there is no conceivable reason that anyone else on the planet should ever need this ever!"
See also: Half of StackOverflow questions.
Which very well might be true, but that was exactly the question: who?
I don't know how commonly it would break that flow, but it certainly could depending on implementation details that are not narrowly prescribed by the OAuth2 spec.
How? Referrer can be easily spoofed.
For example you might not know that important site X linked to you and is driving Y% of your audience. You are not necessarily interested in the individuals following the links when you discover that.
If so then please mark your link up as NSFW/NSFL.
I hate sharing Amazon shopping links because Amazon packs much referrer as possible in the link. Amazon uses the referrer to track who am I sharing to and use it for data for them to sells.