Live data from Hacker News

How we hacked McKinsey's AI platform

codewall.ai

141–150 of 213 posts

Re: How we hacked McKinsey's AI platform

#141
post #21

I've got no idea who codewall is. Is there acknowledgment from McKinsey that they actually patched the issue referenced? I don't see any reference to "codewall ai" in any news article before yesterday and there's no names on the site. https://www.google.com/search?q=codewall+ai

We’re pretty new! :) They didn’t want to provide comment on our post but they did offer comment via The Register.

Re: How we hacked McKinsey's AI platform

#142

Earlier quoted context omitted.

Founder of CodeWall here. It's quite funny because whilst an LLM did write the bulk of the posts factual content (based on the agents findings), I wrote the intro and summary at the end. That's just my writing style. Feel free to read my personal blog to compare: https://darkport.co.uk

Idk how big your team is of course but imo try to hire a technical writer (they’re really cheap now), it pays dividends for a long time as consistent style and keywords build up SEO reputation. This article is making the rounds, some bigger papers picked it up, it is very valuable to land it well.

Thanks for the suggestion, will look into it.

Re: How we hacked McKinsey's AI platform

#144
post #72

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

is this the same at quantumblack? They at least give the impression their assets on Brix are somewhat up to date and uesable

QB is no more, leadership left, technical experts left. Just the brand stayed behind.

Re: How we hacked McKinsey's AI platform

#145

Earlier quoted context omitted.

The only people who hire McKinsey are execs who are even more clueless than the consultants.

The executives who hire McKinsey are often not clueless, but they often lack the political power in the company to push through their plans. So they hire some well-regarded business consultancy to get an "objective" analysis what needs to be done.

In my experience, McKinsey often gets brought in from the very top - who should be able to push through more or less what they want. They just want a scapegoat in case things go wrong.

Re: How we hacked McKinsey's AI platform

#146
post #44
post #3

Why was there a public endpoint? Surely this should all have been behind the firewall and accessible only from a corporate device associated mac address?

> accessible only from a corporate device associated mac address Like that ever stopped anyone. That's just a checkbox item.

wot?

Re: How we hacked McKinsey's AI platform

#148
post #131
post #122

Earlier quoted context omitted.

Great money?

According to levels the pay band caps out around $250k and a principal title. It's good but probably not enough for most to put up with the culture long term.

When you get to partner level, you also get profit sharing on top of you salary.

Partners get 300-400k and senior partners get closer to 600-800

Re: How we hacked McKinsey's AI platform

#149

Earlier quoted context omitted.

The only people who hire McKinsey are execs who are even more clueless than the consultants.

The executives who hire McKinsey are often not clueless, but they often lack the political power in the company to push through their plans. So they hire some well-regarded business consultancy to get an "objective" analysis what needs to be done.

The version I've heard is that you can pin the blame on the consultants if it goes wrong.
Post reply on HN