Something that caught my eye though: links now have a rel="noreferrer" option. This sounds like a pretty bad idea. It's not supported by any browsers yet, but if it worked it would blank out the referrer field on HTTP requests you make after clicking on a link.
There are only two use cases I can imagine:
1. You have some super-secret URL's that are not protected by any other authentication method, you want to avoid others sniffing them out from the referrer field. Verdict: your security is broken and cannot be saved by any standards body.
2. You're hosting a site with malicious XSS-loaded links and want to hide your tracks. OR you are executing CSRF attacks and want to hide your tracks. Verdict: this rel value is perfect for you.