Permissions on macOS
Periscopes sets itself up through Apple’s own APIs, and macOS asks you before each step that changes how your Mac handles traffic.
The first run, from install to routed traffic. Purple boxes are where macOS asks you to approve something. On Macs managed with the Periscopes MDM profile, both are approved in advance and you won’t see them.
What macOS asks for
Section titled “What macOS asks for”| Permission | When macOS asks | What it allows | How to turn it off |
|---|---|---|---|
| Network extension | During setup, after you click Install Extension | Lets Periscopes see outbound TCP connections on ports 80 and 443 and pass them to the proxy. | Switch Enabled off in the menu bar, or turn Periscopes off in System Settings → General → Login Items & Extensions → Network Extensions. |
| Proxy configuration | Right after the extension is installed | Makes the extension the Mac’s transparent proxy. It’s listed as Periscopes in System Settings → VPN & Filters. | Remove the Periscopes entry in System Settings → VPN & Filters. |
| Notifications | The first time the proxy becomes unreachable | Tells you when traffic stops being inspected. | System Settings → Notifications → Periscopes. |
What Periscopes doesn’t do
Section titled “What Periscopes doesn’t do”- It doesn’t run in the kernel. The network extension is an ordinary process that macOS starts, stops and can remove.
- It doesn’t send your traffic anywhere else. The extension only connects to the proxy address set in the app,
127.0.0.1:8089by default. - It doesn’t cut you off. If the proxy isn’t running, connections go straight out, and the menu bar shows that they aren’t being inspected.
- It doesn’t touch UDP. DNS and QUIC go out as usual.