Live data from Hacker News

How we hacked McKinsey's AI platform

codewall.ai

71–80 of 213 posts

Re: How we hacked McKinsey's AI platform

#71

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

I am not sure what accounting or management consulting firms are doing in tech.

They look to package up something and sell it as long as they can.

AI solutions won't have enough of a shelf life, and the thought around AI is evolving too quickly.

Very happy to be wrong and learn from any information folks have otherwise.

Re: How we hacked McKinsey's AI platform

#72

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

is this the same at quantumblack? They at least give the impression their assets on Brix are somewhat up to date and uesable

Re: How we hacked McKinsey's AI platform

#73
post #70

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

Maybe it was opened up so it could be used in recruiting? McKinsey challenges graduates to use AI chatbot in recruitment overhaul: https://www.ft.com/content/de7855f0-f586-4708-a8ed-f0458eb25...

Using a 2 year old paradigm.

And require a chatbot to be used that can be easily gamed by asking a model of how best to navigate it lol.

Implementing the past of AI practices is requesting something that will be easily outdone.

Re: How we hacked McKinsey's AI platform

#74
post #71

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

I am not sure what accounting or management consulting firms are doing in tech. They look to package up something and sell it as long as they can. AI solutions won't have enough of a shelf life, and the thought around AI is evolving too quickly. Very happy to be wrong and learn from any information folks have otherwise.

The purpose of hiring them is to make them come to the conclusion you already have, so when it goes well you get the credit for doing it, or if it goes sideways you can pin the blame on them.

Re: How we hacked McKinsey's AI platform

#75
post #8

> This was McKinsey & Company — a firm with world-class technology teams [...] Not exactly the word on the street in my experience. Is McKinsey more respected for software than I thought? Otherwise I'm curious why TFA didn't just politely leave this bit out.

No, they don't have world class technology teams, they hire contractors to do all the tech stuff, their expertise is in management, yes that's world class.

Yes, world class in causing human suffering.

https://www.youtube.com/watch?v=Q7pgDmR-pWg

Re: How we hacked McKinsey's AI platform

#76

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

Couple of things to add:

McKinsey has a weird structure where there are too many cooks in the kitchen.

Everybody there is reviewed on client impact, meaning it ends up being an everybody-for-themselves situation.

So as a developer you have little guidance (in fact, you're still being reviewed on client impact, even if you have 0 client exposure).

Then a (Senior) Partner comes in with this idea (that will get them a good review), and you jump on that. After all, it's all you can do to get a good review.

You work on it, and then the (Senior) Partner moves on. But it's not done. It's enough for the review, but continuing to work on it doesn't bring you anything, in fact, it will actually pull you down, as finishing the project doesn't give immediate client results.

So what does this mean? Most products of McKinsey are a grab-bag of raw ideas of leadership, implemented as a one-off, without a cohesive vision or even a long-term vision at all. It's all about the review cycle.

McKinsey is trying to do software like they do their other engagements. It doesn't work. You can't just do something for 6 months and then let it go. Software rots.

The fact that they laid off a good amount of (very good) software engineers in 2024 is a reflection on how they see software development.

And McKinsey's people, who go to other companies, take those ideas with them. Result: The UI of your project changes all the time, because everybody is looking at the short-term impact they have that gets them a good review, not what is best for the project in the long term.

Re: How we hacked McKinsey's AI platform

#77
post #26

Earlier quoted context omitted.

Those short "punchy sentence" paragraphs are my new trigger: > No credentials. No insider knowledge. And no human-in-the-loop. Just a domain name and a dream. It just sounds so stupid.

Founder of CodeWall here. It's quite funny because whilst an LLM did write the bulk of the posts factual content (based on the agents findings), I wrote the intro and summary at the end. That's just my writing style. Feel free to read my personal blog to compare: https://darkport.co.uk

If you really DID come up with that paragraph 100% completely on your own with no LLM influence then...I apologize for the insult, though I can't really back out from what I said. It's still a bombastic way of saying very little.

Re: How we hacked McKinsey's AI platform

#80
post #71

Earlier quoted context omitted.

I am not sure what accounting or management consulting firms are doing in tech. They look to package up something and sell it as long as they can. AI solutions won't have enough of a shelf life, and the thought around AI is evolving too quickly. Very happy to be wrong and learn from any information folks have otherwise.

The purpose of hiring them is to make them come to the conclusion you already have, so when it goes well you get the credit for doing it, or if it goes sideways you can pin the blame on them.

Or, alternatively, there are so many companies that are weak on tech they pay for someone else to guide them.
Post reply on HN