CP67 was an abbreviation for control program 67 for the IBM 360/67 computer of, right, about 1967 and was developed by the IBM Cambridge Scientific Center as a means of interactive, time-sharing development of operating systems.
Later commercial time-sharing services used CP67. So, could have a few dozen users, each writing whatever code they wanted, e.g., assembler since it was a good environment to make developing assembler code easy, with, as far as I know, no user ever hurting the CP67 code or the work of any other user.
So, right, CP67 was the first or one of the first cases of virtual machine. Its security provisions appeared to be absolute -- run any code at all, including privileged code, e.g., including operating systems, including CP67 itself, with full safety and security.
Two years or so later there was Multics from MIT Project MAC. It featured capabilities and attribute control lists (still with us). As far as I know, they worked fine. For some years there was a Multics in the basement of the Pentagon and regarded as secure computing. Later Prime Computer did something quite similar and claimed that they had a prize for anyone who could break their security.
Later IBM revised CP67 and called it VM, and since then it has been from common to standard for the IBM mainframe operating systems to run on VM instead of on the bare metal. There have been decades of high end production systems running on VM. I haven't heard about any security holes.
As of a few years ago, a list from Microsoft of security holes fixed included at least one based on a "buffer overflow" bug. Gads: If as recently as a few years ago Microsoft still had buffer overflow bugs, one has to question if by then they much cared about computer security at all. Buffer overflow bugs -- that's Programming 101 for middle school.
I just checked Firefox 35.0.1 and couldn't find where to turn off JavaScript. For the Web pages at my Web site, I have so far not written a single line or character of JavaScript and hope never to, although Microsoft's ASP.NET does write some for me -- and I do wish I knew what ASP.NET classes or options I used to cause Microsoft to write any JavaScript for me.
The old first rule of computer security was to separate code and data, and never but never let data from an untrusted source run as data. Never. Not once. For any reason.
So, in light of this first rule, we have JavaScript downloaded with the HTML text and markup of a Web page and executed. So, I want a very, very, very clear, careful, rock solid, expertly reviewed, as close as possible to proofs of correctness evidence that it is impossible, absolutely, positively totally, without any possibly of exception, for code, any code at all that could possibly exist, in JavaScript that could cause my computer any problems at all, and otherwise just block it. Nothing to do with it. Dump it.
Computer viruses have cost me about half my time so far this year, and I want nothing to do with more computer viruses. JavaScript? Totally glad to junk it.
As I recall, not so long ago, Firefox had Java enabled by default! Outrageous. And at times in Microsoft's Internet Explorer had to be careful to disable Active X, which could run any code at all.
JavaScript? I want nothing to do with pull downs, pop-ups, roll-overs, the screen jumping around for no good reason, etc. Just HTML and CSS -- fine with me.
HTML was just a word-whacking mark-up language -- fine. But, yes, for user input it has text boxes, multi-line text boxes, check boxes, and radio buttons. Okay. Should be able to implement those safely enough.
Can we start to take computer security seriously? When are we going to start?
E.g., Microsoft has gone from Windows NT to 2000, XP, Vista, 8, 8.1 etc., but where in there is the solid security? They have the Start button, remove it, put it back, the Metro interface, tablets, phones, etc., but what about computer security?
I don't give even one weak little hollow hoot about touch screens, but I care a lot about computer security.