Set up a bunch of servers all over the internet with innocuous web pages. Get all of them to include in their SSL headers the exact identical timestamp of July 5th 1998.
Then get the user to connect to all those domains (eg. with a page with a bunch of iframes).
The Secure Time service will see that lots of remote servers all agree with high confidence that the date is July 5th 1998. So the system clock gets set to then.
Then you use a leaked yet expired cert (or maybe one signed with a broken algorithm) to impersonate an update server or steal valuable cookies/tokens.
Expired certs typically fall out the back of revocation systems too - so it really is just the expiry date/time that protects against their use.