this reads like it was written by an LLM
How we hacked McKinsey's AI platform
171–180 of 213 posts
Re: How we hacked McKinsey's AI platform
#172Earlier quoted context omitted.
The executives who hire McKinsey are often not clueless, but they often lack the political power in the company to push through their plans. So they hire some well-regarded business consultancy to get an "objective" analysis what needs to be done.
How can it be that what you just wrote is such a widely known fact? I've been reading this and hearing this from consultancy people as well for many years now. If the guy lacks the political power, why don't his internal political opponents say, "nice try hiring the consultants, but we know this trick very well, you still don't get it your way". It has to be some kind of higher level protection racket or something. L…
Aside, there's a lot of stuff online re McKinsey. I suggest searching HN plus also search "Confessions of a McKinsey Whistleblower" in your fave web search engine.
My favourite was the LRB article "When McKinsey comes to town" -- see https://news.ycombinator.com/item?id=33869800
Re: How we hacked McKinsey's AI platform
#173Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…
Couple of things to add: McKinsey has a weird structure where there are too many cooks in the kitchen. Everybody there is reviewed on client impact, meaning it ends up being an everybody-for-themselves situation. So as a developer you have little guidance (in fact, you're still being reviewed on client impact, even if you have 0 client exposure). Then a (Senior) Partner comes in with this idea (that will get them a g…
Re: How we hacked McKinsey's AI platform
#174Earlier quoted context omitted.
> [...] US with a 4.0 GPA from a top ten university. They're not very bright, most of them. the top students from the top ten universities in the US produce... mostly not very bright people? this is getting even stranger to the rest of us plebians. sometimes i am left in awe of how different my world is from some of you here
How different the world is? But your credentials worship fits right in with this community. Ideologically aligned if nothing else. Well we can all at least imagine being some 4.0 Ivy League dude who only interacts with 4.0 Ivy League dudes. He’s not going to think that everyone he interacts with range from merely brilliant to the most studious-enlightened hardworking top of the morning fellow (or whatever adjectives…
What did I see at the university? Very hard working people. Very interesting research. Very shallow knowledge outside a narrow domain expertise.
These are the folks McKinsey hires... but these shallow thinkers are sent on 6 week projects for companies in industry they hadn't even heard before.
Once, no one in the team knew what product CompanyX sold... CompanyX is a a top tier multinational consumer product brand that routinely sponsors sports events, including TV ads.
Re: How we hacked McKinsey's AI platform
#175Earlier quoted context omitted.
> [...] US with a 4.0 GPA from a top ten university. They're not very bright, most of them. the top students from the top ten universities in the US produce... mostly not very bright people? this is getting even stranger to the rest of us plebians. sometimes i am left in awe of how different my world is from some of you here
How different the world is? But your credentials worship fits right in with this community. Ideologically aligned if nothing else. Well we can all at least imagine being some 4.0 Ivy League dude who only interacts with 4.0 Ivy League dudes. He’s not going to think that everyone he interacts with range from merely brilliant to the most studious-enlightened hardworking top of the morning fellow (or whatever adjectives…
worship is an extremely strong word for a one-sentence casual comment.
but yeah, by default i will file anyone with a 4.0 from a top 10 school in the "brighter than me" category. is that worship?
Re: How we hacked McKinsey's AI platform
#176Earlier quoted context omitted.
I just wonder how much professional grade code written by LLMs, "reviewed" by devs, and commited that made similar or worse mistakes. A funny consequence of the AI boom, especially in coding, is the eventual rise in need for security researchers.
In fairness although "the industry" learns best practices like using SQL prepared statements, not sanitising via blacklists, CSFR, etc. there's a constant new stream of new programmers who just never heard of these things. It doesn't help that often when these things are realised the only way we prevent it in future is by talking about it, which doesn't work for newbies. Nobody goes and fixes SQL APIs so that you can…
Re: How we hacked McKinsey's AI platform
#177Earlier quoted context omitted.
The executives who hire McKinsey are often not clueless, but they often lack the political power in the company to push through their plans. So they hire some well-regarded business consultancy to get an "objective" analysis what needs to be done.
The version I've heard is that you can pin the blame on the consultants if it goes wrong.
Re: How we hacked McKinsey's AI platform
#178Earlier quoted context omitted.
Analysis: 1. How do I build a datacenter 2. How is the industrial ceramic market structured, how do they perform 3. How does a changing environment impact life insurance Strategy: 1. Should I build a datacenter 2. Should I invest in an industrial ceramics company 3. Should I divest my life insurance subsidiary Specifically in the software world this would be "automate some esoteric ERP migration" or "build this data…
These look like questions you would give to AI in 2026.
The problem is AI isn't CYA quality (yet) to your board.
Re: How we hacked McKinsey's AI platform
#179Earlier quoted context omitted.
if you don't have sufficient political clout or influence, you seek sponsorship or backing from others with it to accrue more influence for your idea. You can pay consultants to agree with your idea and produce pretty charts and whitepapers for it.
The question is, why does anyone take the word of a company seriously which will agree with any idea if you pay them? After several iterations of this game (decades by now), someone would surely say "nah, we don't care about these charts and whitepapers, we know that the company who made them will agree with anything for money, so it's still a NO" My hunch is that in fact they won't agree with just any idea. There is…
Look at NEOM in Saudi.
McKinsey took 130M in a year to recommend a 500B investment in a 105 mile city in the desert. Sunk 50B and project was revised to take 50 years and 8 trillion.
It's impressive salesmanship how they were able to bilk such a large sum and support interim approvals for the regime to launder favors. I can see people wanting that "conflict."
Re: How we hacked McKinsey's AI platform
#180Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…
Couple of things to add: McKinsey has a weird structure where there are too many cooks in the kitchen. Everybody there is reviewed on client impact, meaning it ends up being an everybody-for-themselves situation. So as a developer you have little guidance (in fact, you're still being reviewed on client impact, even if you have 0 client exposure). Then a (Senior) Partner comes in with this idea (that will get them a g…