Ok, I didn't realize that. But it still doesn't solve the problem of compromising an old certificate and creating a fake signature with your own time.
To do this, you'd need to compromise or convince a trusted timestamping authority to sign your signing request with an old date.