They don't even need to be falsified, because if the site that had the link is on SSL then the header won't even be sent.
blank header = no access to my big picture
That does mean people with referrer turned off in their browser are inconvenienced, but they've done it deliberately and know how to undo it for my site. And if people can be arsed to falsify headers, they're welcome to my pictures, since they are putting in far more effort than the meagre reward deserves. As I said, it's not perfect, but then neither is the lock on my front door - even I know half a dozen ways somebody could get through my door without either stealing my key or asking my permission, and I'm not that interested in physical security hardware hacks so there are probably six more that I've never heard of.
blank header = no access to my big picture
That does mean people with referrer turned off in their browser are inconvenienced, but they've done it deliberately and know how to undo it for my site. And if people can be arsed to falsify headers, they're welcome to my pictures, since they are putting in far more effort than the meagre reward deserves. As I said, it's not perfect, but then neither is the lock on my front door - even I know half a dozen ways somebody could get through my door without either stealing my key or asking my permission, and I'm not that interested in physical security hardware hacks so there are probably six more that I've never heard of.