Influential works and references:
- Testing Metrics for Password Creation Policies by Attacking Large Sets of Revealed Passwords by Matt Weir, Susdhir Aggarwal, Michael Collins, Henry Stern
- An Administrator’s Guide to Internet Password Research by Dinei Florencio, Cormac Herley, and Paul C. van Oorschot
- Password strength Wikipedia article has very useful references section
- PasswordsCon - conference on passwords and authentication topics (twice a year).