Earlier quoted context omitted.
What prevents the user from simply setting their clock forward? (I do agree cert pinning is bad overall.)
If the user wants to ignore cert error they're going to ignore cert errors
1. All-powerful NSA types who've managed to steal a CA's private key or get a certificate mis-issued. It's a nigh-irreplaceable attack opportunity, but the moment they use it it'll be revoked within hours, so naturally it's reserved for the absolute highest value target. For example, [1]
2. Users trying to reverse-engineer your app.
You can imagine which of these is the most common - perhaps you don't want the user to be able to bypass the pin, even intentionally.
[1] https://www.eff.org/deeplinks/2011/08/iranian-man-middle-att...