Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Anthropic Mythos -- We've Opened Pandora's Box

Mike's Notes

This is why Pipi Core is in its own data centre, physically isolated from the internet, to ensure 100% security and protect people's privacy.

I endorse Steve Blank's conclusion. The risks are enormous and growing.

Resources

References

  • Reference

Repository

  • Home > Ajabbi Research > Library > Subscriptions > Steve Blank
  • Home > Handbook > 

Last Updated

01/05/2026

Anthropic Mythos -- We've Opened Pandora's Box

By: Steve Blank
The Cipher Brief: 23/04/2026

Adjunct Professor at Stanford and Co-founder of the Gordian Knot Center for National Security Innovation

Steve Blank is an adjunct professor at Stanford and co-founder of the Gordian Knot Center for National Security Innovation. His book, The Four Steps to the Epiphany is credited with launching the Lean Startup movement. He created the curriculum for the National Science Foundation Innovation Corps. At Stanford, he co-created the Department of Defense Hacking for Defense and Department of State Hacking for Diplomacy curriculums. He is co-author of The Startup Owner's Manual.

EXPERT OPINION

For a decade the cybersecurity community was predicting a cyber apocalypse tied to a single event - the day a Cryptographically Relevant Quantum Computer could run Shor’s algorithm and break the public-key cryptography systems most of the internet runs on. We braced for a one-time shock we would absorb and adapt to. The National Institute for Standards and Technology (NIST) has already published standards for the first set of post-quantum cryptography codes.

It’s possible that the first cybersecurity apocalypse may have come early. Anthropic Mythos now tilts the odds in the cybersecurity arms race in favor of attackers - and the math of why it tilts, and how long it stays tilted, is different from anything our institutions were built to handle.

In 2013, Edward Snowden changed what people knew

In 2013, Edward Snowden changed what people understood about nation-state cyber capabilities. In the decade that followed disclosures and leaks of nation state cyber tools reduced uncertainty and accelerated the diffusion of cyber tradecraft.

The defensive playbook that followed - compartmentalization, need-to-know, leak-surface reduction, clearance reform, “worked” because the Snowden leaks and those that followed were one-time disclosures, absorbed over a decade, with the system returning to something like equilibrium.

We got good at responding to the shocks of disclosures. It became doctrine. It was the right doctrine for the wrong future.

Pandora's Box

In 2026, Anthropic Mythos (and similar AI systems) is changing what people can do. Mythos found Zero-day vulnerabilities and thousands of “bugs” that were not publicly known to exist (a must read article here.) Many of these were not just run-of-the-mill stack-smashing exploits but sophisticated attacks that required exploiting subtle race conditions, KASLR (Kernel Address Space Layout Randomization) bypasses, memory corruption vulnerabilities and logic flaws in cryptographic libraries in cryptography libraries, and bugs in TLS, AES-GCM, and SSH.

The reality is a number of these were not “bugs.” There were nation-state exploits built over decades.

What this means is that Anthropic Mythos, and the tools that will certainly follow, has exposed hacking tools previously only available to nation-states and transformed into tools that Script Kiddies will have within a few months (and certainly within a year.) No expertise will be required to apply that tradecraft, compressing both the learning curve and the execution barrier.

All Government’s Will Scramble

When Mythos-class systems are used to analyze the code in critical infrastructure and systems, the hidden sophisticated zero-day exploits that are already in use, (including ones nation-states have been sitting on for years) will be found and patched. That means intelligence agency sources of how to collect information will go dark as companies and governments patch these vulnerabilities.

Every serious intelligence service will scramble, likely with their own AI, to find new access before the visibility gap costs them something they cannot replace. A new generation of AI-driven exploits will rise to replace the ones that have been burned.This will build an arms race with a new generation of AI-driven cyber exploits looking to replace the ones that have been discovered. Whichever side sustains faster AI adoption - not just “procures” it, but ships it into operational systems, holds a widening advantage measured in powers of two every four months.

The binding constraint is not budget. Not authority. Not access to models. It is institutional capacity for change - the rate at which a defender organization can actually change what it deploys.

The Long Tail Will Not Be Patched

Anthropic has given companies early access to secure the world’s most critical software. That will help Fortune 100 companies. But the Fortune 100 is not just a small part of the software attack surface.

The attack surface includes the unpatched county water utility, the regional hospital, the third-tier defense supplier, the school district, the state Department of Motor Vehicles, the municipal 911 system, and the small-town electric co-op. Tens of thousands of systems running software nobody has time to patch, maintained by teams that have never heard of KASLR.

Every one of those systems is now exposed to nation-state-grade tradecraft, wielded by attackers with no expertise required. Mythos-class hardening at the top of the pyramid does not trickle down. The long tail will stay unpatched for years.

Attackers Advantage - For Now

Under continuous exponential growth of AI designed cyberattacks, a cyber defender using traditional tools can't just respond just once and stabilize their systems. They’ll need to keep investing at a rate that matches the offense's growth rate itself. A one-time defensive shock like compartmentalization might work against a sudden attack, but it will fail against sustained exponential pressure because there's no stable equilibrium to return to. The defender's investment rate has to track the offense's growth rate.

Ultimately and hopefully, the next generation of AI driven cyber-defense tools will create a new equilibrium.

What We Need to Do

Mythos and its follow-ons will change how we think about cyber-defense. We can’t just build a set of features to catch every exploit x or y. We need to build cyber systems that can maintain or exceed the capability rate of the attackers.

Here are the three tools governments and cyber defense companies need to build now:

  1. Measure the Gap Between Attackers and Defenders. We need to know the gap between what the attackers can do and what we can defend against. We need to develop instrumented red/blue exercises (a simulation of a cyberattack, where two teams – the red team and the blue team – are pitted against each other) to estimate the number of new vulnerabilities vs cyber defense mitigation. (This can be built in six months, with a small team.)
  2. Measure the Defender Response Time. For each corporate or government mission system, measure how long it takes to implement a change from identification to production deployment. Treat each organizational obstacle as equivalent to technical debt that needs to be remediated.
  3. Specify Speed, Not Features. Any new Cyber Defense tools and architecture - including the next-generation cloud-native systems sitting in review right now - should have explicit ‘rate’ requirements. Claims of “our product delivers X capability is now the wrong specification. “Closes detection gap at rate greater than or equal to the offense growth rate” is the right one.

Buckle up. It's going to be a wild ride - for companies, for defense and for government agencies.

Mythos is a sea change. It requires a different response than what the current cyber security ecosystem was built for, and one the current system is not built to produce. We are not behind yet. The gap between Mythos and what we can build to defend is small enough today that a serious response can still match it. A year from now, the same response will be eight times too slow. Two years, sixty-four.

By the way, the only thing left in Pandora’s Box was hope.

ManageMyHealth breach: Patients at risk of identity theft, extortion - experts

Mike's Notes

There is never an excuse for these security breaches. Sloppy work created the vulnerability.

"Private health records, linked to the Manage My Health ransomware attack, appear to have already surfaced on the dark web, revealing patients’ most delicate medical details online.

Screenshots seen by The Post appear to show about 30 patient files, seemingly from multiple individuals, including intimate details of a 2018 head injury, a July 2025 vaginal swab, and a December 2025 heart attack." - Stuff

 NZ uses an opt‑in model.

  • Health information is governed by the Health Information Privacy Code 2020, which requires explicit patient consent for new forms of access.
  • Identity verification is required before enabling online access, which naturally fits an opt‑in workflow

NZ portal vendors include

  • ConnectMed
  • Health 365
  • ManageMyHealth
  • MyIndici
  • Vensa
  • MediMap

Updates

  • Second health provider, Canopy Health, hit in major cyber attack - RNZ
  • Patient data changed as major NZ health app MediMap hacked - RNZ

Resources

References

  • Reference

Repository

  • Home > Ajabbi Research > Library >
  • Home > Handbook > 

Last Updated

25/02/2026

ManageMyHealth breach: Patients at risk of identity theft, extortion - experts

By: Ruth Hill
RNZ: 5/01/2026

Reporter

What I cover: I mainly cover health stories. It's a critically important subject that touches all of our lives, and the goal of my coverage is to shine a light on inequities where they exist and examine some of the complexities in a way that makes sense. At their heart, health stories are always about people, and I love giving a voice to patients and the incredible people working in frontline health services.

My background: I joined RNZ in 2009 as a senior reporter, based in the Wellington newsroom.

Contact: If you have an idea for a story or feedback for me, feel free to get in touch - ruth.hill@rnz.co.nz.

This ransom post screenshot is from a popular hacking forum. Photo: Supplied

  • Hackers say ManageMyHealth ransomware attack about 'business'
  • Company has until Tuesday morning to pay up or 400,000 patient documents released
  • Cyber security experts fear some patients at risk of blackmail or identity theft
  • Patient health portal criticised for sluggish response

Thousands of patients caught up in the ManageMyHealth ransomware attack could be at risk of identity theft or extortion, cyber security experts are warning.

The hackers, calling themselves "Kazu", posted on Sunday morning that unless the company paid a ransom within 48 hours, they would leak more than 400,000 files in their possession.

In a post on Telegram, the group purporting to be behind the breach said it had brought forward the deadline from 15 January in part because ManageMyHealth had responded faster than expected, but mainly to "put pressure on the company".

"Their ignorance of our emails and messages, along with their failure to acknowledge users or explain exactly what happened, is the main issue. Many MMH users have been asking the company for an explanation, but they've either ignored them or responded with vague statements."

This deadline escalation statement was shared in a Telegram channel run by Kazu regarding the ManageMyHealth data breach.This deadline escalation statement was shared in a Telegram channel run by Kazu. Photo: Supplied

Kazu said it had opted for a low-ball ransom demand of $60,000 "to protect the data and quickly close the deal".

"But it seems the company doesn't care about their users' data."

The hackers indicated they were prepared to leak the "valuable" data just to make a point.

"We know exactly how valuable health data is and how sensitive it can be.

"Even if the company doesn't pay the ransom, we can still find buyers for this data.

"To prove our claims and increase the chances of successful deals in the future, we decided to leak the data for free if they don't pay the ransom."

Kazu said they were "not a hacktivist group with political motives".

"We're doing this as a business. Our main goal is money and building a good reputation in the community."

The hackers claimed to have successfully extracted ransom money from many healthcare companies in Asia and Africa over the last two months.

"Once the company pays, we send them a copy of the data, delete it from our servers and never post anything related to the company again."

Patients at risk

Samples for potential "buyers" included clinical notes, lab results, vaccination records, medical photographs and personal identification details, including names, birth dates, addresses, emails and phone numbers.

IT consultant and Hornby community board member Cody Cooper was signed up to ManageMyHealth through his GP.

"My clinic has got 20,000 patients so there's a real push for online. It's seen as convenient, but patients don't have a lot of choice."

He went online to verify the veracity of the claims and was horrified by what he found.

"There's people's passports, there's people's ADHD documents from a psychiatrist, there's pictures of people unclothed. It's very personal data. And my concern as a patient would be, will someone blackmail people? Or try to extort them personally as well, if they don't pay up?"

From what had been made visible so far, it did not appear the data had been encrypted, Cooper said.

"You can infer this fairly safely because resetting passwords doesn't cause users to 'lose' their stored documents. If the data had been encrypted properly with keys tied to credentials, access would break when credentials change."

He also questioned why ManageMyHealth took so long to respond.

"The hack was published around 10pm on 29 December, the MMH website notice appeared on the afternoon of 31 December, but the site wasn't taken offline until that evening."

Furthermore, the company was taking too long to inform affected clinics and patients, he said.

"It should have been able to determine the extent of the breach relatively quickly. The fact that, days later there is no clear confirmation about what was accessed or copied is worrying."

However, there was no guarantee that giving in to the hackers' demands would solve the problem for MMH, he said.

"They may still release the data anyway, they may still contact people, we have no way of knowing if they will honour it.

"Furthermore, if that person is from a country with sanctions, there are laws and treaties that forbid that payment from being made legally as well."

Patients were just collateral damage, he said.

"I will personally probably look to close my account. I can't really have confidence in the system after this. Hopefully my clinic will find a solution that's better."

'Big wakeup call' - Health Minister

The Health Minister said the cyber breach of the country's largest patient information portal was a "big wakeup call".

Simeon Brown told Morning Report he was incredibly concerned.

"It's a deeply serious situation," he said.

"I've been briefed a number of times by health officials who are working very closely with ManageMyHealth in regard to the notification process."

He said ManageMyHealth was also working with the Privacy Commissioner and the National Cyber Security Centre, who were providing them with advice around the notification process.

Brown said his expectation was that they do it as quickly as possible, but they also had to do it accurately as well, and in compliance with the Privacy Act.

"There's a number of processes they have to go through. My expectation is that they do that as quickly as possible so that patients who have had data breached are aware of that and of what data has been breached," he said.

Brown said the advice he's received was that the cyber hackers had only released a very small portion of data as part of their attempt in order to receive a ransom payment.

There was a forensic process underway at the moment to go through and identify who's been impacted and then the process of notification, which is what Manage My Health was doing, he said.

Brown said the group were using hacked information in order to receive a financial reward, but they did not know where they were operating from.

"The reality is that here is a big wakeup call in terms of the protection of private health data and their need for that to be held in the most secure form possible so that patients can have confidence in how it is being used," he said.

Hackers building their 'brand'

Data journalist Keith Ng said the hackers appeared to be using ManageMyHealth to leverage a bigger payout from one of their other targets: Saudi Icon Ransom.

"They're implying they've got their hands full and don't want to be distracted by small fry here, that's their explanation for wanting this over quickly - and if they don't get their ransom they will release data for free."

For Kazu, it was an exercise in brand management.

"They want to establish themselves as a 'trustworthy' ransomware group. By that they mean 'If you pay us, we'll delete the data and you'll never hear from us again. If you don't pay us, bad things will happen to you'.

"So they want to build up their business and use the New Zealand dataset to make an example out of, so people will take them more seriously in the future."

Unfortunately, the ManageMyHealth breach was unlikely to be the result of a sophisticated hacking operation, Ng said.

"This is probably a couple of days work for a couple of people. It's not like an elite hacking crew, it's about volume and they want to make sure they've got targets on the hook all the time.

"They poke around and try to find common vulnerabilities, flaws, they're really looking for low hanging fruit - and if they don't find it, they move on quickly to the next target."

Over and above the technical question of which part of ManageMyHealth's system was not secure, the more important question was what processes it had in place, whether it was having regular independent security audits and taking action to fix the problems identified, he said.

"A business that sets itself up as a health information management system has a lot of incentive to do things right because when they fail, really catastrophic things like this happen, and it is an existential risk for them.

"So we should expect better from these businesses and the fact they let this one slip past them, they should be held accountable."

In its public statements, ManageMyHealth appeared to be trying to minimise the scale of the problem, Ng said.

"They're saying only 7 percent of users were affected, but 7 percent of 1.8 million is quite a big number. The other thing they've said is 'only one component' of the site is affected, not the core database. But it's the kind of things in there - medical photos, test results - which make it so sensitive and damaging for people who are affected.

"It's probably the worst data breach that I recall seeing in New Zealand so far."

Aura Information Security's Patrick Sharp said medical records were hugely valuable to criminals.

The Medibank ransomware attack in Australia in 2022 resulted in many thousands - "maybe even hundreds of thousands" of real financial crimes, he said.

"It's quite likely that the 126,000 or so people affected - depending on the kind of information involved - may suffer at the hands of criminal gangs, lots of scams, blackmail, those kind of things."

ManageMyHealth has been approached for comment.

PostHog analytics

Mike's Notes

I plan to experiment with using PostHog for analytics. They are very open about their products. I have copied their approach and applied it to Ajabbi.com. The Ajabbi Handbook, for example, is based on the PostHog Handbook. I'm also creating a ribbon menu based on what PostHog does.

I need analytics to discover how to improve Pipi and provide an excellent service to developers. I'm not doing this to invade people's privacy and sell ads.

They have a generous free tier, which should work for the early startup stages.

Ways to install

  • JS snippet
  • Libraries
  • Frameworks
  • API

I will start including their code using JS snippets on web pages in the next few weeks.

Resources

References

  • Reference

Repository

  • Home > Ajabbi Research > Library > Subscriptions > PostHog
  • Home > Handbook > 

Last Updated

18/05/2025

Article

By: 
PostHog: 19/09/2024

Installation instructions

"This is the simplest way to get PostHog up and running. It only takes a few minutes.

Copy the snippet below and replace <ph_project_api_key> and <ph_client_api_host> with your project's values, then add it within the <head> tags at the base of your product - ideally just before the closing </head> tag. This ensures PostHog loads on any page users visit.

You can find the snippet pre-filled with this data in your project settings." - PostHog

Code

HTML

<script>

    !function(t,e){var o,n,p,r;e.__SV||(window.posthog=e,e._i=[],e.init=function(i,s,a){function g(t,e){var o=e.split(".");2==o.length&&(t=t[o[0]],e=o[1]),t[e]=function(){t.push([e].concat(Array.prototype.slice.call(arguments,0)))}}(p=t.createElement("script")).type="text/javascript",p.async=!0,p.src=s.api_host+"/static/array.js",(r=t.getElementsByTagName("script")[0]).parentNode.insertBefore(p,r);var u=e;for(void 0!==a?u=e[a]=[]:a="posthog",u.people=u.people||[],u.toString=function(t){var e="posthog";return"posthog"!==a&&(e+="."+a),t||(e+=" (stub)"),e},u.people.toString=function(){return u.toString(1)+".people (stub)"},o="capture identify alias people.set people.set_once set_config register register_once unregister opt_out_capturing has_opted_out_capturing opt_in_capturing reset isFeatureEnabled onFeatureFlags getFeatureFlag getFeatureFlagPayload reloadFeatureFlags group updateEarlyAccessFeatureEnrollment getEarlyAccessFeatures getActiveMatchingSurveys getSurveys getNextSurveyStep onSessionId".split(" "),n=0;n<o.length;n++)g(u,o[n]);e._i.push([i,s,a])},e.__SV=1)}(document,window.posthog||[]);

    posthog.init('<ph_project_api_key>', {api_host: 'https://us.i.posthog.com', person_profiles: 'identified_only'})

</script>

ShareThis vs AddToAny

Mike's Notes

The Ajabbi website needs a simple way for people to print, email, or share any web page on social media. Tracking is not required, as it is against Ajabbi's privacy policy.

ShareThis is one option, and it's free. 

I have some questions.

  • Is it safe?
  • Why is it free?
  • Are there any privacy issues?
  • Can any tracking be turned off?
  • Is it reliable?
  • Is it WAIG accessible?
  • How does it compare with other social bookmarking websites?

I concluded that ShareThis was breaching users' privacy. I am now using AddToAny, which anonymises the data collected.

I don't know where this information came from below.

Resources

References

  • Reference

Repository

  • Home > Ajabbi Research > Library >
  • Home > Handbook > 

Last Updated

18/05/2025

Article

By: Mike Peters
On a Sandy Beach: 20/04/2025

Mike is the inventor and architect of Pipi and the founder of Ajabbi.

Wikipedia

"A social bookmarking website is a centralized online service that allows users to store and share Internet bookmarks. Such a website typically offers a blend of social and organizational tools, such as annotation, categorization, folksonomy-based tagging, social cataloging and commenting. The website may also interface with other kinds of services, such as citation management software and social networking sites. ..." - Wikipedia

"ShareThis is a technology company headquartered in Palo Alto, CA, with offices in New York, Chicago, and Los Angeles. It offers free website tools and plugins for online content creators. ShareThis collects data on user behavior, and provides this to advertisers and technology companies for ad targeting, analytics, and customer acquisition purposes. ShareThis has an exclusive license with the University of Illinois for patent applications made by co-founder David E. Goldberg. The patents include genetic algorithms and machine learning technologies used for the purposes of information collection and discovery based on a user's sharing behavior. ..." - Wikipedia

ShareThis Instructions

How to Reinitialize ShareThis Buttons With Specific Sharing Parameters
In this guide, we’ll teach you how to reinitialize (reload) our ShareThis buttons to use specific sharing parameters. By default the ShareThis widget loader loads as soon as the browser encounters the JavaScript tag; typically in the tag of your page. ShareThis assets are generally loaded from a CDN closest to the user. However, if you wish to change the default setting so that the widget loads after your web page has completed loading then you simply set a parameter in the page.

Reinitializing the buttons would allow you to:

  • Take control of when to display the buttons, for example, until a modal or pop-up opens up.
  • Have different instances of the buttons on the same page with different configurations, for example, if you want to display only the Twitter button on a specific part and the Facebook one on another. Or if you want to have different languages on different sets of buttons.
  • Auto refresh share button properties when new links are loaded with share buttons (infinite scroll).
Note: If you don’t want to reinitialize the buttons with specific parameters, you could just use the window.__sharethis__.initialize() function as it is whenever your modal, pop-up, etc. activates. Please note that you may have to set a delay of around 0.3 to 1 second before adding the line of code above to give time for the container to appear, otherwise, the function will be called too soon.

Add <div> and Javascript code

// render the html
// load the buttons window.__sharethis__.load('inline-share-buttons', {/* this is where your configurations must be, read the Configuration section */

Once you’ve added the above portion of the code, you’re now able to include any or all of the following configuration options below.

Configuration Options

config = { 
   alignment: STRING, // left, right, center, justified.
   container: STRING, // id of the dom element to load the buttons into
   enabled: BOOLEAN,
   font_size: INTEGER, // small = 11, medium = 12, large = 16.
   id: STRING, // load the javascript into a specific dom element by id attribute
   labels: STRING, // "cta", "counts", or "none"
   language: STRING   // IETF language tag in which the buttons' labels are,
   min_count: INTEGER, // minimum amount of shares before showing the count
   padding: INTEGER, // small = 8, medium = 10, large = 12.
   radius: INTEGER, // in pixels
   networks: ARRAY[STRING],
   show_total: BOOLEAN,
   show_mobile_buttons: BOOLEAN, // forces sms to show on desktop
   use_native_counts: BOOLEAN, // uses native facebook counts from the open graph api
   size: INTEGER, // small = 32, medium = 40, large = 48.
   spacing: INTEGER, // spacing = 8, no spacing = 0.
};
  

Example

// render the html
// load the buttons window.__sharethis__.load('inline-share-buttons', { alignment: 'left', id: 'my-inline-buttons', enabled: true, font_size: 11, padding: 8, radius: 0, networks: ['messenger', 'twitter', 'pinterest', 'sharethis', 'sms', 'wechat'], size: 32, show_mobile_buttons: true, spacing: 0, url: "https://www.sharethis.com", // custom url title: "My Custom Title", language: "en", image: "https://18955-presscdn-pagely.netdna-ssl.com/wp-content/uploads/2016/12/ShareThisLogo2x.png", // useful for pinterest sharing buttons description: "My Custom Description", username: "ShareThis" // custom @username for twitter sharing });

Available Networks

Social Service data-network Code
Black Lives Matter blm
Blogger blogger
Buffer buffer
Copy Link copy
Diaspora diaspora
Digg digg
Douban douban
Email email
Evernote evernote
Facebook facebook
Flipboard flipboard
Gmail gmail
Google Bookmarks googlebookmarks
Hacker News hackernews
Instapaper instapaper
iOrbix iorbix
Kakao kakao
Koo App kooapp
Line line
Linkedin linkedin
LiveJournal livejournal
Mail.Ru mailru
Meneame meneame
Messenger messenger
Odnoklassniki odnoklassniki
Outlook outlook
Pinterest pinterest
Pocket getpocket
Print print
Push to Kindle kindleit
Qzone qzone
Reddit reddit
Refind refind
Renren renren
Skype skype
Surfingbird surfingbird
Telegram telegram
Tencent QQ tencentqq
Threema threema
Trello trello
Tumblr tumblr
Twitter twitter
Viber viber
VK vk
WeChat wechat
ShareThis sharethis
Sina Weibo weibo
SMS sms
Snapchat snapchat
WhatsApp whatsapp
WordPress wordpress
Xing xing
Yahoo Mail yahoomail
Yummly yummly

Lazy loading and ShareThis tools

The ShareThis tools load/display only the first time the site loads. In case you are using tools like the Image Share Buttons or Video Share Buttons and your site uses lazy loading or similar technologies you will need to reinitialize the tools once newer elements appear.

Since ShareThis searches for the images/embedded videos on that occasion only, and the images closer to the bottom aren’t loaded yet, ShareThis doesn’t know of their existence even if they do load later on, and won’t display the buttons on them.

As a workaround for this, the Javascript code below will check every 3 seconds if any scrolling is done, if so, it will reinitialize the buttons. We are using the scrolling as a way to know if the images have loaded; since the images load once a visitor scrolls to that specific part.

//state variable for scrolling
let scrolling = false;

//in case of scrolling, change the state of the scrolling variable to true
window.onscroll = function() {
scrolling = true;
}
/*create an interval that checks every 3 seconds the state of the scrolling variable, if any scrolling has been done in that interval, reinitialize the buttons*/

setInterval(() => {
if (scrolling) {
scrolling = false;
window.sharethis.initialize()
}
}, 3000);

Notes

Please keep in mind that Open Graph tags will take precedence when sharing on Facebook and other social channels. If linking to a custom URL, please be sure to have Open Graph tags filled out for that page as well.

As with our other tools, we recommend moving the site to live production before giving it a try as there are some resources that aren’t passed during a local/test environment.

Order of Precedence

It is important to remember the order of precedence by which the ShareThis code processes share properties. Generally, we recommend using one approach by which sharing properties are specified on your pages to prevent errors.

  • Any dynamically specified JavaScript properties (i.e. highest precedence)
  • Properties specified in tags (i.e. second precedence)
  • Open Graph Protocol tags (i.e. lowest precedence)