Skip to content

Permissions on macOS

Periscopes sets itself up through Apple’s own APIs, and macOS asks you before each step that changes how your Mac handles traffic.

Periscopes app menu bar app macOS System Settings Network extension system extension 1 install the extension system extension request Allow Periscopes in System Settings 2 install and launch outside the kernel 3 add the proxy configuration VPN & Filters: Periscopes Allow adding proxy configurations 4 start it connect the configuration 5 claim outbound TCP 80/443 UDP is left alone

The first run, from install to routed traffic. Purple boxes are where macOS asks you to approve something. On Macs managed with the Periscopes MDM profile, both are approved in advance and you won’t see them.

PermissionWhen macOS asksWhat it allowsHow to turn it off
Network extensionDuring setup, after you click Install ExtensionLets Periscopes see outbound TCP connections on ports 80 and 443 and pass them to the proxy.Switch Enabled off in the menu bar, or turn Periscopes off in System Settings → General → Login Items & Extensions → Network Extensions.
Proxy configurationRight after the extension is installedMakes the extension the Mac’s transparent proxy. It’s listed as Periscopes in System Settings → VPN & Filters.Remove the Periscopes entry in System Settings → VPN & Filters.
NotificationsThe first time the proxy becomes unreachableTells you when traffic stops being inspected.System Settings → Notifications → Periscopes.
  • It doesn’t run in the kernel. The network extension is an ordinary process that macOS starts, stops and can remove.
  • It doesn’t send your traffic anywhere else. The extension only connects to the proxy address set in the app, 127.0.0.1:8089 by default.
  • It doesn’t cut you off. If the proxy isn’t running, connections go straight out, and the menu bar shows that they aren’t being inspected.
  • It doesn’t touch UDP. DNS and QUIC go out as usual.