Live data from Hacker News

How we hacked McKinsey's AI platform

codewall.ai

131–140 of 213 posts

Re: How we hacked McKinsey's AI platform

#131
post #122

Earlier quoted context omitted.

Why would anyone work there, then, unless that's the only place they could get hired as a dev? And if the latter is the case, then that sort of stamps the case closed from the get-go...

Great money?

According to levels the pay band caps out around $250k and a principal title. It's good but probably not enough for most to put up with the culture long term.

Re: How we hacked McKinsey's AI platform

#133
post #131
post #122

Earlier quoted context omitted.

Great money?

According to levels the pay band caps out around $250k and a principal title. It's good but probably not enough for most to put up with the culture long term.

>[...] the pay band caps out around $250k [...] probably not enough for most [...]

an absolutely wild statement to 99.9+% of the world

Re: How we hacked McKinsey's AI platform

#134

Earlier quoted context omitted.

The only people who hire McKinsey are execs who are even more clueless than the consultants.

The executives who hire McKinsey are often not clueless, but they often lack the political power in the company to push through their plans. So they hire some well-regarded business consultancy to get an "objective" analysis what needs to be done.

How can it be that what you just wrote is such a widely known fact? I've been reading this and hearing this from consultancy people as well for many years now. If the guy lacks the political power, why don't his internal political opponents say, "nice try hiring the consultants, but we know this trick very well, you still don't get it your way".

It has to be some kind of higher level protection racket or something. Like if you hire the consultants there is some kind of kickbacks to the higherups or something with more steps involved where those who previously opposed it will now accept it if it's rubberstamped by the consultants.

Or perhaps those other players who are politically opposing this person are just dummies and don't know about this trick and actually trust the consultants. Or maybe it's a bit of a check, that you can't get anything and everything rubberstamped by the consultants, so it is some kind of sanity filter that the guy isn't proposing something that only benefits himself and screws everyone else.

And if it's the latter, then it is genuine value, a somewhat impartial second opinion. Basically there is a fog-of-war for all the execs regarding all the internal politics going on, it's not like they see through everything all the time and simply refuse to take the obviously correct decision for no reason.

Re: How we hacked McKinsey's AI platform

#135

Earlier quoted context omitted.

Couple of things to add: McKinsey has a weird structure where there are too many cooks in the kitchen. Everybody there is reviewed on client impact, meaning it ends up being an everybody-for-themselves situation. So as a developer you have little guidance (in fact, you're still being reviewed on client impact, even if you have 0 client exposure). Then a (Senior) Partner comes in with this idea (that will get them a g…

I'm far from being an expert, but it sounds like this company needs some consultancy.

Can McKinsey fund McKinsey by consulting for McKinsey? Could we oroborus corporate consulting so that those consultants could be trapped in a loop and those of us doing useful work wouldn't need to interact with them anymore?

Re: How we hacked McKinsey's AI platform

#136

Earlier quoted context omitted.

Their model works great. It’s really about bypassing the existing power structure of the company. Competence of the work itself is a secondary objective. Most in-house initiatives can be slow rolled by management. The fresh faced consultant with 2-3 steps to access the CEO neutralizes that. It seems grifty but is really exploiting bugs in corporate governance. The current fad of firing the managers is a riff on this.…

This somehow implies that initiatives or strategies from consultants are somewhat successful. This is not the case in my experience.

No, you misunderstood. It is not about their output, it almost never is.

Most of the times, the business decision has already been made long before McK is hired. It’s all about legitimizing that decision and making it happen.

You can also wield them as a weapon against internal competitors or opponents. Look up how they were used to kill off Cariad for example.

Re: How we hacked McKinsey's AI platform

#137

Earlier quoted context omitted.

The executives who hire McKinsey are often not clueless, but they often lack the political power in the company to push through their plans. So they hire some well-regarded business consultancy to get an "objective" analysis what needs to be done.

How can it be that what you just wrote is such a widely known fact? I've been reading this and hearing this from consultancy people as well for many years now. If the guy lacks the political power, why don't his internal political opponents say, "nice try hiring the consultants, but we know this trick very well, you still don't get it your way". It has to be some kind of higher level protection racket or something. L…

if you don't have sufficient political clout or influence, you seek sponsorship or backing from others with it to accrue more influence for your idea. You can pay consultants to agree with your idea and produce pretty charts and whitepapers for it.

Re: How we hacked McKinsey's AI platform

#138

Earlier quoted context omitted.

How can it be that what you just wrote is such a widely known fact? I've been reading this and hearing this from consultancy people as well for many years now. If the guy lacks the political power, why don't his internal political opponents say, "nice try hiring the consultants, but we know this trick very well, you still don't get it your way". It has to be some kind of higher level protection racket or something. L…

if you don't have sufficient political clout or influence, you seek sponsorship or backing from others with it to accrue more influence for your idea. You can pay consultants to agree with your idea and produce pretty charts and whitepapers for it.

The question is, why does anyone take the word of a company seriously which will agree with any idea if you pay them? After several iterations of this game (decades by now), someone would surely say "nah, we don't care about these charts and whitepapers, we know that the company who made them will agree with anything for money, so it's still a NO"

My hunch is that in fact they won't agree with just any idea. There is a limit to how extreme the idea can get, though probably the filter is indeed weak. Still, without this filter, people would propose even wilder ideas that maximize their own expected payoff at the expense of other players, so just the fact that it has to be signed off by an external party is still enough information for the powerful decision makers that they are willing to fund their services.

Re: How we hacked McKinsey's AI platform

#139

> One of those unprotected endpoints wrote user search queries to the database. The values were safely parameterised, but the JSON keys — the field names — were concatenated directly into SQL. I was expecting prompt injection, but in this case it was just good ol' fashioned SQL injection, possible only due to the naivety of the LLM which wrote McKinsey's AI platform.

I just wonder how much professional grade code written by LLMs, "reviewed" by devs, and commited that made similar or worse mistakes. A funny consequence of the AI boom, especially in coding, is the eventual rise in need for security researchers.

In fairness although "the industry" learns best practices like using SQL prepared statements, not sanitising via blacklists, CSFR, etc. there's a constant new stream of new programmers who just never heard of these things. It doesn't help that often when these things are realised the only way we prevent it in future is by talking about it, which doesn't work for newbies. Nobody goes and fixes SQL APIs so that you can only pass compile-time constant strings as the statement or whatever. Newbies just have to magically know to do that.

Re: How we hacked McKinsey's AI platform

#140

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

Couple of things to add: McKinsey has a weird structure where there are too many cooks in the kitchen. Everybody there is reviewed on client impact, meaning it ends up being an everybody-for-themselves situation. So as a developer you have little guidance (in fact, you're still being reviewed on client impact, even if you have 0 client exposure). Then a (Senior) Partner comes in with this idea (that will get them a g…

Those comments are spot on.

McKinsey was on a spree to become the best tech consulting company and brought a lot of great tech talent but the 2023 crisis made leadership turn 180 and simply ditch/ignore all the tech experts they brought to the firm.

All the expertise has left the firm and now they are more and more becoming another BS tech consulting firm, with strategy folks that don't even know that ML is AI advising clients on Enterprise AI transformation.

The tech initiative was a failure and Lilli's problem is just a symptom of it.

I wonder what was the experience at Bain and BCG

Post reply on HN