Live data from Hacker News

How we hacked McKinsey's AI platform

codewall.ai

201–210 of 213 posts

Re: How we hacked McKinsey's AI platform

#201
post #122

Earlier quoted context omitted.

Why would anyone work there, then, unless that's the only place they could get hired as a dev? And if the latter is the case, then that sort of stamps the case closed from the get-go...

Great money?

Years ago, I was at a Big4; had a co-worker whose spouse was working for MCK; we had more or less the same salary at the Big4, but spose at MCK was getting more or less exactly the double amount.

Then I listened and we started to calculate:

- In the MCK Office from 0900 - 2300 on MO-FR

- In the MCK Office from 1000 - 1600/1700 on SA

- Often in the MCK Office from 1000-1400 on SU

Overall, yes: The amont was the double amount - but in the end working hours were also roughly the double.

Re: How we hacked McKinsey's AI platform

#202

Earlier quoted context omitted.

How different the world is? But your credentials worship fits right in with this community. Ideologically aligned if nothing else. Well we can all at least imagine being some 4.0 Ivy League dude who only interacts with 4.0 Ivy League dudes. He’s not going to think that everyone he interacts with range from merely brilliant to the most studious-enlightened hardworking top of the morning fellow (or whatever adjectives…

I was a B/B- student from a foreign top 100 university. I don't know how I got accepted to a top 5 engineering school in the US. I accepted and ended my PhD with a 3.3. Im not very bright or hardworking. What did I see at the university? Very hard working people. Very interesting research. Very shallow knowledge outside a narrow domain expertise. These are the folks McKinsey hires... but these shallow thinkers are se…

In consulting it is "maximum self confidence by having minium knowledge at the same time" :-D

Re: How we hacked McKinsey's AI platform

#203

I don’t love the title here. Maybe this is a “me” problem, but when I see “AI agent does X,” the idea that it might be one of those molt-y agents with obfuscated ownership pops into my head. In this case, a group of pentesters used an AI agent to select McKinsey and then used the AI agent to do the pentesting. While it is conventional to attribute actions to inanimate objects (car hits pedestrians), IMO we should be…

The article does say

> No human in the loop

If true, it's quite irresponsible. They are admitting to allowing a agent to autonomously execute code on the network. Autonomously perform hacking activities.

Re: How we hacked McKinsey's AI platform

#204

Earlier quoted context omitted.

I was a B/B- student from a foreign top 100 university. I don't know how I got accepted to a top 5 engineering school in the US. I accepted and ended my PhD with a 3.3. Im not very bright or hardworking. What did I see at the university? Very hard working people. Very interesting research. Very shallow knowledge outside a narrow domain expertise. These are the folks McKinsey hires... but these shallow thinkers are se…

In consulting it is "maximum self confidence by having minium knowledge at the same time" :-D

The product that I am referring to that companyX makes was probably used today, in some form, by >80% of the global population this morning.

Everyone would recognize it. Cartoons have made jokes about these product since the dawn of animation.

CompanyX makes is the premier manufacturer of these.

Think as pervasive and obvious as sneakers made by Nike, but it wasn't footwear.

And yet only one person in a team of a dozen consultants had ever heard of the company they'd been hired for.

Re: How we hacked McKinsey's AI platform

#206
post #135

Earlier quoted context omitted.

Can McKinsey fund McKinsey by consulting for McKinsey? Could we oroborus corporate consulting so that those consultants could be trapped in a loop and those of us doing useful work wouldn't need to interact with them anymore?

Have you seen current AI deals? This IS the future, but so much more efficient than requiring OpenAI, NVidia, MS, Amazon, etc. all be involved.

What do you mean exactly?

Re: How we hacked McKinsey's AI platform

#207

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

Couple of things to add: McKinsey has a weird structure where there are too many cooks in the kitchen. Everybody there is reviewed on client impact, meaning it ends up being an everybody-for-themselves situation. So as a developer you have little guidance (in fact, you're still being reviewed on client impact, even if you have 0 client exposure). Then a (Senior) Partner comes in with this idea (that will get them a g…

this is why working at mckinsey seems like a horrible proposition to me, personally

Re: How we hacked McKinsey's AI platform

#208
post #98

Earlier quoted context omitted.

They generally hire smart people who are good at a combination of: - understanding existing systems - what the paint points are - making suggestions on how to improve those systems given the paint points - that includes a mix of tech changes, process updates and/or new systems etc Now, when it comes to implementing this, in my experience it usually ends up being the already in place dev teams. Source: worked at a lar…

My take*: McKinsey hiring largely selects for staying calm under pressure and presenting a confident demeanor to clients. Verbal fluency with decision-making frameworks goes a long way. Having strong analytical skills seemed essential; hopefully the bar for "sufficiently analytical" has raised along with general data science skills in industry. I don't view them as top-tier experts in their own right, whether it be s…

[flagged]

Re: How we hacked McKinsey's AI platform

#209
post #80

Earlier quoted context omitted.

The purpose of hiring them is to make them come to the conclusion you already have, so when it goes well you get the credit for doing it, or if it goes sideways you can pin the blame on them.

Or, alternatively, there are so many companies that are weak on tech they pay for someone else to guide them.

Having done some work with these F500 companies, this is part of it. These legacy companies have long seen tech as a cost center, haven't invested in it, and are unable to attract talent. And, for whatever reason, these companies insist on working with large consulting firms, when a dedicated software or tech consulting firm that is smaller would be way better.

Ultimately, why would a large company hire a consultancy company that is bad at tech and has a lot of bad processes to do their tech for them? Because the company itself is even worse and doesn't know what good looks like. If you are hiring McKinsey or Deloitte to do your tech, it's because you are completely lost and don't have the slightest clue how to become unlost. And you have no concept of what good looks like.

If you think the actual tech talent and systems are bad, when you work with these consulting firms, they are going to do the most heavy SAFe process you have ever seen. For me, the worst part is not the tech talent, but rather the most by-the-book, heavy-handed agile process possible. Everything moves way slower because of this "agile" rot, and there is almost no concept of doing proper ideation and prototyping work.

These legacy F500 companies try to do everything cheaply with consultants and offshoring, and yet it always ends up costing way more than it would if they just had proper in-house tech talent.

Re: How we hacked McKinsey's AI platform

#210

[flagged]

Lol, dead internet theory is rapidly becoming reality on HN.

Another LLM bot down thread [0] produced the exact same slop down to the “no X, no Y, no Z.”

> the data leak is bad but the write access to system prompts is what keeps me up at night. they could silently rewrite how Lilli responds to 43k consultants with a single UPDATE statement - no deploy, no code review, no logs.

[0] https://news.ycombinator.com/item?id=47345670

Post reply on HN