Live data from Hacker News

How we hacked McKinsey's AI platform

codewall.ai

121–130 of 213 posts

Re: How we hacked McKinsey's AI platform

#121
post #29

I don’t love the title here. Maybe this is a “me” problem, but when I see “AI agent does X,” the idea that it might be one of those molt-y agents with obfuscated ownership pops into my head. In this case, a group of pentesters used an AI agent to select McKinsey and then used the AI agent to do the pentesting. While it is conventional to attribute actions to inanimate objects (car hits pedestrians), IMO we should be…

Yah it's just an ad, and "Pentesting agents finds low-hanging vulnerability" isn't gonna drive clicks.

... at a massive company

That's important. Cloudwall isn't really saying they have some secret sauce here, but it's noteworthy who they nabbed.

Re: How we hacked McKinsey's AI platform

#122

Earlier quoted context omitted.

Couple of things to add: McKinsey has a weird structure where there are too many cooks in the kitchen. Everybody there is reviewed on client impact, meaning it ends up being an everybody-for-themselves situation. So as a developer you have little guidance (in fact, you're still being reviewed on client impact, even if you have 0 client exposure). Then a (Senior) Partner comes in with this idea (that will get them a g…

Why would anyone work there, then, unless that's the only place they could get hired as a dev? And if the latter is the case, then that sort of stamps the case closed from the get-go...

Great money?

Re: How we hacked McKinsey's AI platform

#123

Earlier quoted context omitted.

Picked up a vibe, but couldn’t confirm it until the last paragraph, but yeah clearly drafted with at least major AI help.

Can we stop softening the blow? This isn't "drafted with at least major AI help", it's just straight up AI slop writing. Let's call a spade a spade. I have yet to meet anyone claiming they "write with AI help but thoughts are my own" that had anything interesting to say. I don't particularly agree with a lot of Simon Willison's posts but his proofreading prompt should pretty much be the line on what constitutes accep…

One thing I've learned recently is a lot guys (like here) have been out here reading each word of a given company's tech blog, closely parsing each sentence construction.. I really cant imagine being even concious of the prose for something like this. A corporate blog, to me, has some base level of banality to it. It's like reading a cereal box and getting angry at the lack of nuance.

Like who cares? Is there really some nostalgia for a time before this? When reading some press release from a cybersecurity company was akin to Joyce or Nabakov or whatever? (Maybe Hemingway...)

We really gotta be picking our battles here imo, and this doesn't feel like a high priority target. Let companies be the weird inhuman things that they are.

Read a novel! They are great, I promise. Then when you read other stuff, maybe you won't feel so angry?

Re: How we hacked McKinsey's AI platform

#124
post #120

Earlier quoted context omitted.

Unfortunately that’s what they are called. I was hoping the phrasing would highlight the problem rather than propagate it.

Eh, if you tell me that I need to do X, then I can make choices on how to accomplish X, that I am no longer an agent as a human? You're trying to redefine long standing definitions for God knows what reason.

The difference is that you are a sentient person who decides to follow my instructions, not just a tool that I use.

Re: How we hacked McKinsey's AI platform

#125

Earlier quoted context omitted.

Couple of things to add: McKinsey has a weird structure where there are too many cooks in the kitchen. Everybody there is reviewed on client impact, meaning it ends up being an everybody-for-themselves situation. So as a developer you have little guidance (in fact, you're still being reviewed on client impact, even if you have 0 client exposure). Then a (Senior) Partner comes in with this idea (that will get them a g…

> McKinsey is trying to do software like they do their other engagements. It doesn't work. I mean, it doesn't work for their consulting gigs either. There's a reason McKinsey has such a bad reputation.

Their model works great.

It’s really about bypassing the existing power structure of the company. Competence of the work itself is a secondary objective. Most in-house initiatives can be slow rolled by management.

The fresh faced consultant with 2-3 steps to access the CEO neutralizes that. It seems grifty but is really exploiting bugs in corporate governance.

The current fad of firing the managers is a riff on this. Every jackass C-level is coming up with the novel idea of flattening.

Re: How we hacked McKinsey's AI platform

#126

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

Couple of things to add: McKinsey has a weird structure where there are too many cooks in the kitchen. Everybody there is reviewed on client impact, meaning it ends up being an everybody-for-themselves situation. So as a developer you have little guidance (in fact, you're still being reviewed on client impact, even if you have 0 client exposure). Then a (Senior) Partner comes in with this idea (that will get them a g…

I'm far from being an expert, but it sounds like this company needs some consultancy.

Re: How we hacked McKinsey's AI platform

#127

Earlier quoted context omitted.

> McKinsey is trying to do software like they do their other engagements. It doesn't work. I mean, it doesn't work for their consulting gigs either. There's a reason McKinsey has such a bad reputation.

But it does work for them? They make tons of money.

Well, fair point. It doesn't work for their clients.

Re: How we hacked McKinsey's AI platform

#128

Earlier quoted context omitted.

But it does work for them? They make tons of money.

As an ex-consultant: consulting at that level is kind of a grift. They over-promise and under-deliver as SOP. It's ripe for AI disruption, whatever that looks like.

Ideally, executives will get replaced by AI soon. Which should actually be easier than engineers. That will kind of solve the consulting problem automatically.

Re: How we hacked McKinsey's AI platform

#129
post #52

Earlier quoted context omitted.

Net conclusion: Don’t hire McKinsey to advise on AI implementation or tech org design and practices if they can’t get it right themselves.

The only people who hire McKinsey are execs who are even more clueless than the consultants.

The executives who hire McKinsey are often not clueless, but they often lack the political power in the company to push through their plans. So they hire some well-regarded business consultancy to get an "objective" analysis what needs to be done.

Re: How we hacked McKinsey's AI platform

#130

Earlier quoted context omitted.

> McKinsey is trying to do software like they do their other engagements. It doesn't work. I mean, it doesn't work for their consulting gigs either. There's a reason McKinsey has such a bad reputation.

Their model works great. It’s really about bypassing the existing power structure of the company. Competence of the work itself is a secondary objective. Most in-house initiatives can be slow rolled by management. The fresh faced consultant with 2-3 steps to access the CEO neutralizes that. It seems grifty but is really exploiting bugs in corporate governance. The current fad of firing the managers is a riff on this.…

This somehow implies that initiatives or strategies from consultants are somewhat successful. This is not the case in my experience.
Post reply on HN