Protecting on referer is a bad idea anyway imho.
Because the referer is sent from the client side, the client will always be able to spoof it.
You also saw this with formmail being abused by spammers, it only relied on the referer
I suggest content providers to move to some other form of authentication, unless the amount of spoofers is low enough to still make a good profit, however with this 'teqnique' getting more and more known the amount of spoofers will rise..