That's definitely not to spec if the browser is doing it. http://tools.ietf.org/html/rfc2616#section-15.1.3
"Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol."
However, it's possible that Facebook is passing users through an HTTP gateway.