I've got no idea who codewall is. Is there acknowledgment from McKinsey that they actually patched the issue referenced? I don't see any reference to "codewall ai" in any news article before yesterday and there's no names on the site. https://www.google.com/search?q=codewall+ai
How we hacked McKinsey's AI platform
141–150 of 213 posts
Re: How we hacked McKinsey's AI platform
#142Earlier quoted context omitted.
Founder of CodeWall here. It's quite funny because whilst an LLM did write the bulk of the posts factual content (based on the agents findings), I wrote the intro and summary at the end. That's just my writing style. Feel free to read my personal blog to compare: https://darkport.co.uk
Idk how big your team is of course but imo try to hire a technical writer (they’re really cheap now), it pays dividends for a long time as consistent style and keywords build up SEO reputation. This article is making the rounds, some bigger papers picked it up, it is very valuable to land it well.
Re: How we hacked McKinsey's AI platform
#143Re: How we hacked McKinsey's AI platform
#144Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…
is this the same at quantumblack? They at least give the impression their assets on Brix are somewhat up to date and uesable
Re: How we hacked McKinsey's AI platform
#145Earlier quoted context omitted.
The only people who hire McKinsey are execs who are even more clueless than the consultants.
The executives who hire McKinsey are often not clueless, but they often lack the political power in the company to push through their plans. So they hire some well-regarded business consultancy to get an "objective" analysis what needs to be done.
Re: How we hacked McKinsey's AI platform
#146Why was there a public endpoint? Surely this should all have been behind the firewall and accessible only from a corporate device associated mac address?
> accessible only from a corporate device associated mac address Like that ever stopped anyone. That's just a checkbox item.
Re: How we hacked McKinsey's AI platform
#147Re: How we hacked McKinsey's AI platform
#148Earlier quoted context omitted.
Great money?
According to levels the pay band caps out around $250k and a principal title. It's good but probably not enough for most to put up with the culture long term.
Partners get 300-400k and senior partners get closer to 600-800
Re: How we hacked McKinsey's AI platform
#149Earlier quoted context omitted.
The only people who hire McKinsey are execs who are even more clueless than the consultants.
The executives who hire McKinsey are often not clueless, but they often lack the political power in the company to push through their plans. So they hire some well-regarded business consultancy to get an "objective" analysis what needs to be done.